CVE-2026-41575

Source
https://cve.org/CVERecord?id=CVE-2026-41575
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41575.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41575
Aliases
  • GHSA-j7wv-7j97-9qh9
Published
2026-05-08T14:42:24.109Z
Modified
2026-08-04T11:50:55.768417555Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
th30d4y/IP: DOM-Based Cross-Site Scripting (XSS) Vulnerability
Details

In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been patched in version 2.0.1.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-80"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41575.json"
}
References

Affected packages

Git / github.com/th30d4y/ip

Affected ranges

Type
GIT
Repo
https://github.com/th30d4y/ip
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.0.1"
        },
        {
            "fixed": "2.0.1"
        }
    ]
}

Affected versions

1.*
1.0.1
1.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41575.json"