GHSA-w3vx-52j6-9fjp

Suggest an improvement
Source
https://github.com/advisories/GHSA-w3vx-52j6-9fjp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w3vx-52j6-9fjp/GHSA-w3vx-52j6-9fjp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w3vx-52j6-9fjp
Aliases
  • CVE-2026-30048
Published
2026-03-18T18:31:18Z
Modified
2026-03-19T13:01:43.876989Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability
Details

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when the chat history is reloaded. The issue is reproducible across multiple independent implementations of the widget, indicating that the vulnerability resides in the product itself rather than in a specific website configuration.

Database specific
{
    "github_reviewed_at": "2026-03-19T12:50:46Z",
    "nvd_published_at": "2026-03-18T18:16:27Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

npm / @developer.notchatbot/webchat

Package

Name
@developer.notchatbot/webchat
View open source insights on deps.dev
Purl
pkg:npm/%40developer.notchatbot/webchat

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w3vx-52j6-9fjp/GHSA-w3vx-52j6-9fjp.json"