GHSA-2f3m-j83v-344cLowCVSS 6.1
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS)...
🔗 CVE IDs covered (1)
📋 Description
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML can be interpreted by the browser, resulting in XSS.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-8656
- https://github.com/benjamine/jsondiffpatch/commit/232338b34c4653148ca2f44e897a765b72c8c98f
- https://gist.github.com/yuki-matsuhashi/72ed072d919f3c52adba298faa6a7da5
- https://security.snyk.io/vuln/SNYK-JS-JSONDIFFPATCH-16635946
- https://github.com/advisories/GHSA-2f3m-j83v-344c