Several cross-site scripting vulnerabilities existed in the deno_doc crate which lead to Self-XSS with deno doc --html.
1.) XSS in generated search_index.js
deno_doc outputed a JavaScript file for searching. However, the generated file used innerHTML on unsanitzed HTML input.
2.) XSS via property, method and enum names
deno_doc did not sanitize property names, method names and enum names.
The first XSS most likely didn't have an impact since deno doc --html is expected to be used locally with own packages.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2024-11-25T19:34:24Z",
"nvd_published_at": "2024-11-25T19:15:09Z",
"severity": "LOW"
}