Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6p6h-rqr6-62mv

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

A flaw was found in GI-DocGen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

Пакеты

Наименование

gi-docgen

pip
Затронутые версииВерсия исправления

< 2025.5

2025.5

EPSS

Процентиль: 27%
0.00343
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
8 месяцев назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

CVSS3: 6.1
nvd
8 месяцев назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

CVSS3: 6.1
debian
8 месяцев назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary ...

suse-cvrf
5 месяцев назад

Security update for python-gi-docgen

EPSS

Процентиль: 27%
0.00343
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79