Clear the Lineup: XSS via innerHTML in cyberbro — Found and Fixed by GSC
What I Fixed A Cross-Site Scripting (XSS) vulnerability in cyberbro (122 ⭐), an open-source OSINT platform. The search highlight feature used .innerHTML with unsanitized user input, allowing reflected XSS in search results. Found by: GSC (Git Security Checker) — self-learning SAST scanner. The Bug File: src/views/SearchView.js The search highlight function took user search terms and injected them…
A Cross-Site Scripting (XSS) vulnerability was discovered in cyberbro, an open-source OSINT platform. The search highlight feature utilized .innerHTML with unsanitized user input, enabling reflected XSS in search results. GSC (Git Security Checker), a self-learning SAST scanner, identified the issue. The bug was located in the src/views/SearchView.js file, where the search highlight function injected user search terms directly into the DOM via .innerHTML.
This allowed attackers to execute JavaScript code in a victim's browser, potentially leading to session hijacking and credential theft. The vulnerability was fixed by replacing .innerHTML with .textContent + explicit mark element creation, ensuring safe DOM manipulation without HTML injection. The impact severity is HIGH (CVSS 7.5), classified as reflected XSS under CWE-79. The fix was merged into the main codebase, addressing the critical security issue.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.