GHSA-95m2-chm4-mq7m: PHP-Textile has persistent XSS vulnerability in image link handling
7.3
CVSS Score
3.1
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
Published
1/7/2025
Updated
1/7/2025
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| netcarver/textile | composer | <= 4.1.2 | 4.1.3 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The commit diff shows a critical modification in Parser.php's fImage method where href validation was added via isValidUrl. Prior to this fix, image links in restricted mode didn't undergo protocol validation, making this function the entry point for unsafe href processing. The vulnerability documentation explicitly states image links were affected while text links were already properly handled, further corroborating fImage as the vulnerable function.