-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows the vulnerable link function in translation.rb added target='_blank' without noopener protection. This matches CWE-1022's description of unsafe window.opener access. The patch explicitly adds rel='noopener' to mitigate this, and tests were updated to verify this protection. The function's role in generating links with external targets directly correlates with the vulnerability description.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| text_helpers | rubygems | >= 1.1.0, < 1.2.0 | 1.2.0 |
Ongoing coverage of React2Shell