Vulnerability DatabaseGHSA-phph-xpj4-wvcv

GHSA-phph-xpj4-wvcv
JavaScript vulnerability analysis and mitigation

Overview

A high-severity Cross-Site Scripting (XSS) vulnerability was identified in hexo-admin, affecting all versions of the package (>=0.0.0). The vulnerability was initially reported on April 14, 2019, and was later published to the GitHub Advisory Database on September 3, 2020, with the identifier GHSA-phph-xpj4-wvcv. This security issue impacts the hexo-admin package, which is a popular npm package (GitHub Advisory).

Technical details

The vulnerability stems from the package's failure to properly sanitize rendered markdown content. This weakness is classified as CWE-79 (Cross-Site Scripting). The vulnerability allows attackers to execute arbitrary JavaScript code in a victim's browser when they have the ability to create new posts. The issue was confirmed through proof-of-concept demonstrations that showed successful exploitation using various payloads, including access to document.cookie and document.domain (Hexo Admin Issue).

Impact

When exploited, this vulnerability enables attackers to execute arbitrary JavaScript code in the context of other users' browsers who access the affected posts. This could potentially lead to theft of sensitive information, session hijacking, or other malicious actions performed in the context of the victim's browser session (GitHub Advisory).

Exploitability

The vulnerability has been demonstrated to be exploitable through the creation of new posts containing malicious payloads. A proof-of-concept exploit has been documented, showing successful execution of various JavaScript commands including access to document.cookie and document.domain (Hexo Admin Issue).

Mitigation and workarounds

Currently, no official fix is available for this vulnerability. The recommended mitigation strategy is to consider using alternative packages until a security fix is made available. Users should exercise caution when using any version of hexo-admin, as all versions are affected by this vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59160HIGH8.8
  • JavaScript logoJavaScript
  • @yeger/turbo-graph
NoYesSep 09, 2026
CVE-2026-59179HIGH8.3
  • JavaScript logoJavaScript
  • @openhop/server
NoYesSep 09, 2026
GHSA-x7m8-jrm8-hpvxHIGH8.1
  • JavaScript logoJavaScript
  • @eigenpal/docx-editor-core
NoYesSep 10, 2026
CVE-2026-59176HIGH7.8
  • JavaScript logoJavaScript
  • functype-mcp-server
NoYesSep 09, 2026
CVE-2026-59158HIGH7.5
  • JavaScript logoJavaScript
  • nuxt-ollama
NoYesSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management