GHSA-rqj3-x344-qvxc

Suggest an improvement
Source
https://github.com/advisories/GHSA-rqj3-x344-qvxc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rqj3-x344-qvxc/GHSA-rqj3-x344-qvxc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rqj3-x344-qvxc
Aliases
  • CVE-2026-30587
Published
2026-03-25T18:31:55Z
Modified
2026-04-02T13:31:55.826944Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Seafile Server has multiple stored XSS vulnerabilities
Details

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properly sanitize WebSocket messages regarding document structure updates. This allows authenticated remote attackers to inject malicious JavaScript payloads via the src attribute of embedded Excalidraw whiteboards or the href attribute of anchor tags.

Database specific
{
    "github_reviewed_at": "2026-04-02T00:00:24Z",
    "nvd_published_at": "2026-03-25T18:16:31Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

npm / @seafile/sdoc-editor

Package

Name
@seafile/sdoc-editor
View open source insights on deps.dev
Purl
pkg:npm/%40seafile/sdoc-editor

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.0.75

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rqj3-x344-qvxc/GHSA-rqj3-x344-qvxc.json"

npm / @seafile/sdoc-editor

Package

Name
@seafile/sdoc-editor
View open source insights on deps.dev
Purl
pkg:npm/%40seafile/sdoc-editor

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.209

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rqj3-x344-qvxc/GHSA-rqj3-x344-qvxc.json"