GHSA-95jq-xph2-cx9h

Suggest an improvement
Source
https://github.com/advisories/GHSA-95jq-xph2-cx9h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-95jq-xph2-cx9h/GHSA-95jq-xph2-cx9h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-95jq-xph2-cx9h
Aliases
Downstream
Published
2025-07-26T00:30:32Z
Modified
2026-09-10T03:50:25Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
Details

Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.

Database specific
{
    "cwe_ids": [
        "CWE-1321"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-07-29T19:09:33Z",
    "nvd_published_at": "2025-07-25T22:15:25Z",
    "severity": "HIGH"
}
References

Affected packages

npm / linkifyjs

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.3.1
Fixed
4.3.2

Affected versions

4.*
4.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-95jq-xph2-cx9h/GHSA-95jq-xph2-cx9h.json"