Urgent.News

What's breaking now, across thousands of outlets.

Tech

Clear the Lineup: XSS via innerHTML in cyberbro — Found and Fixed by GSC

What I Fixed A Cross-Site Scripting (XSS) vulnerability in cyberbro (122 ⭐), an open-source OSINT platform. The search highlight feature used .innerHTML with unsanitized user input, allowing reflected XSS in search results. Found by: GSC (Git Security Checker) — self-learning SAST scanner. The Bug File: src/views/SearchView.js The search highlight function took user search terms and injected them…

A Cross-Site Scripting (XSS) vulnerability was discovered in cyberbro, an open-source OSINT platform. The search highlight feature utilized .innerHTML with unsanitized user input, enabling reflected XSS in search results. GSC (Git Security Checker), a self-learning SAST scanner, identified the issue. The bug was located in the src/views/SearchView.js file, where the search highlight function injected user search terms directly into the DOM via .innerHTML.

This allowed attackers to execute JavaScript code in a victim's browser, potentially leading to session hijacking and credential theft. The vulnerability was fixed by replacing .innerHTML with .textContent + explicit mark element creation, ensuring safe DOM manipulation without HTML injection. The impact severity is HIGH (CVSS 7.5), classified as reflected XSS under CWE-79. The fix was merged into the main codebase, addressing the critical security issue.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

llama.cpp

Article URL: https://llama.app Comments URL: https://news.ycombinator.com/item?id=49267928 Points: 260 # Comments: 114

Your .active Class Is Lying to Screen Readers

If I had to guess the single most common code smell in front-end projects, it wouldn't be a missing semicolon or a messy folder structure — it would be this: .hidden { display : none ; } .disabled {…

More from Wednesday 12 August →