Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.
History

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Jsondiffpatch Project
Jsondiffpatch Project jsondiffpatch
Vendors & Products Jsondiffpatch Project
Jsondiffpatch Project jsondiffpatch

Thu, 11 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 05:15:00 +0000

Type Values Removed Values Added
Description Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2025-09-11T05:00:02.071Z

Updated: 2025-09-11T13:09:13.093Z

Reserved: 2025-09-03T08:48:06.729Z

Link: CVE-2025-9910

cve-icon Vulnrichment

Updated: 2025-09-11T13:09:08.597Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-11T05:15:34.137

Modified: 2025-09-11T17:14:10.147

Link: CVE-2025-9910

cve-icon Redhat

No data.