GHSA-7xvh-c266-cfr5

Suggest an improvement
Source
https://github.com/advisories/GHSA-7xvh-c266-cfr5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7xvh-c266-cfr5/GHSA-7xvh-c266-cfr5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7xvh-c266-cfr5
Aliases
Published
2025-11-17T18:15:55Z
Modified
2025-11-17T18:57:55Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome message
Details

Description

Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a "welcome message", which is HTML that is to be rendered on the login page for branding purposes.

When rendering the welcome message, Dependency-Track versions before 4.13.6 did not properly sanitize the HTML, allowing arbitrary JavaScript to be executed.

Impact

Users with the SYSTEM_CONFIGURATION permission (i.e., administrators), can exploit this weakness to execute arbitrary JavaScript for users browsing to the login page.

Patches

The issue has been fixed in version 4.13.6.

References

  • The issue was introduced via: https://github.com/DependencyTrack/frontend/pull/986
  • The issue was fixed via: https://github.com/DependencyTrack/frontend/pull/1378

Credit

Thanks to Jonas Benjamin Friedli for identifying and responsibly disclosing the issue.

Database specific
{
    "nvd_published_at": "2025-11-17T18:15:58Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed_at": "2025-11-17T18:15:55Z"
}
References

Affected packages

npm / @dependencytrack/frontend

Package

Name
@dependencytrack/frontend
View open source insights on deps.dev
Purl
pkg:npm/%40dependencytrack/frontend

Affected ranges

Type
SEMVER
Events
Introduced
4.12.0
Fixed
4.13.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7xvh-c266-cfr5/GHSA-7xvh-c266-cfr5.json"