Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6p6h-rqr6-62mv

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

A flaw was found in GI-DocGen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

Пакеты

Наименование

gi-docgen

pip
Затронутые версииВерсия исправления

< 2025.5

2025.5

EPSS

Процентиль: 1%
0.00011
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
13 дней назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

CVSS3: 6.1
nvd
13 дней назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

CVSS3: 6.1
debian
13 дней назад

A flaw was found in the gi-docgen. This vulnerability allows arbitrary ...

EPSS

Процентиль: 1%
0.00011
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79