Description
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
Published: 2026-01-26
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6p6h-rqr6-62mv GI-DocGen vulnerable to Reflected XSS via unescaped query strings
History

Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Gnome
Gnome gi-docgen
Vendors & Products Gnome
Gnome gi-docgen

Mon, 26 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
Title Gi-docgen: reflected dom xss in gi-docgen
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-01-26T21:02:29.343Z

Reserved: 2025-10-13T13:26:57.703Z

Link: CVE-2025-11687

cve-icon Vulnrichment

Updated: 2026-01-26T21:02:26.797Z

cve-icon NVD

Status : Deferred

Published: 2026-01-26T20:16:07.817

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-11687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-27T09:03:19Z

Weaknesses