GHSA-w765-jm6w-4hhj

Suggest an improvement
Source
https://github.com/advisories/GHSA-w765-jm6w-4hhj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w765-jm6w-4hhj
Aliases
Published
2025-09-10T17:13:45Z
Modified
2025-09-10T17:13:45Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
Webrecorder packages are vulnerable to XSS through 404 error handling logic
Details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter requestURL (derived from the original request target) is directly embedded into an inline <script> block without sanitization or escaping.

This allows an attacker to craft a malicious URL that executes arbitrary JavaScript in the victim’s browser.

The scope may be limited by CORS policies, depending on the situation in which wabac.js is used.

Patches

The vulnerability is fixed in wabac.js v2.23.11.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-10T17:13:45Z",
    "nvd_published_at":  "2025-09-09T21:15:38Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @webrecorder/wabac

Package

Name
@webrecorder/wabac
View open source insights on deps.dev
Purl
pkg:npm/%40webrecorder/wabac

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.23.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"

npm / replaywebpage

Package

Name
replaywebpage
View open source insights on deps.dev
Purl
pkg:npm/replaywebpage

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"

npm / @webrecorder/archivewebpage

Package

Name
@webrecorder/archivewebpage
View open source insights on deps.dev
Purl
pkg:npm/%40webrecorder/archivewebpage

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.15.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"