GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=ShowBase64offsets('%3Cscript substring.
{
"nvd_published_at": "2026-04-29T04:16:41Z",
"severity": "HIGH",
"github_reviewed_at": "2026-05-06T22:09:27Z",
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true
}