-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The XSS vulnerability stems from two key issues: 1) The absence of URL validation in the StatusCheck model's endpoint field permitted arbitrary input, including JavaScript payloads. 2) The template rendering logic for error messages disabled HTML escaping, allowing these payloads to execute when the endpoint value was included in error outputs. The combination of improper input validation and unsafe output rendering created a stored XSS vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cabot | pip | <= 0.11.16 |
Ongoing coverage of React2Shell