Impact
A flaw was discovered in rhukster dom‑sanitizer's URL Validation component, where the function isDangerousUrl can be manipulated to inject malicious script code into browsers. The vulnerability allows an attacker to execute arbitrary client‑side code by supplying crafted URLs, leading to potential data theft, session hijacking, or other malicious actions that compromise the confidentiality and integrity of users who interact with the affected application. The published exploit demonstrates that this attack can be performed remotely, meaning that any user accessing a vulnerable URL could be affected without additional interaction steps from the attacker.
Affected Systems
The vulnerability affects the rhukster dom‑sanitizer component implemented by rhukster, specifically versions up to and including 1.0.15. The recommended fix is to upgrade to version 1.0.16 or later, which incorporates the patch commit 4623b565d060bc02ca5a07d8c8241fe28e2edfda.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level. The EPSS score is currently not available, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the fact that an exploit has already been published and can be leveraged remotely means that the likelihood of real‑world abuse is non‑negligible. Attackers can target the vulnerable component with user‑controlled URLs, implying that environments dependent on this library should address the issue promptly.
OpenCVE Enrichment