Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh64-4crj-2mxj

Опубликовано: 22 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.

Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.

EPSS

Процентиль: 8%
0.0003
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
7 месяцев назад

Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.

EPSS

Процентиль: 8%
0.0003
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79