CVE-2024-27926

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27926
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27926.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-27926
Aliases
Published
2024-03-06T20:36:04Z
Modified
2025-11-04T19:33:04Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
RSSHub Cross-site Scripting vulnerability caused by internal media proxy
Details

RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.d8ca915, ahen the specially crafted image is supplied to the internal media proxy, it proxies the image without handling XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code. Users who access the deliberately constructed URL are affected. This vulnerability was fixed in version 1.0.0-master.d8ca915. No known workarounds are available.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/diygod/rsshub

Affected ranges

Type
GIT
Repo
https://github.com/diygod/rsshub
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed