Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20497-1

Опубликовано: 09 апр. 2026
Источник: suse-cvrf

Описание

Security update for python-gi-docgen

This update for python-gi-docgen fixes the following issues:

  • CVE-2025-11687: Fixed reflected DOM XSS (bsc#1251961)

Список пакетов

openSUSE Leap 16.0
python3-gi-docgen-2025.5-160000.1.1

Описание

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page - enabling DOM access, session cookie theft and other client-side attacks - via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).


Затронутые продукты
openSUSE Leap 16.0:python3-gi-docgen-2025.5-160000.1.1

Ссылки