{"id":"CVE-2019-15532","details":"CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.","aliases":["GHSA-jp6r-xcjj-5h7r"],"modified":"2026-08-07T15:18:33.069414Z","published":"2019-08-26T12:15:11.657Z","references":[{"type":"FIX","url":"https://github.com/gchq/CyberChef/commit/01f0625d6a177f9c5df9281f12a27c814c2d8bcf"},{"type":"FIX","url":"https://github.com/gchq/CyberChef/compare/v8.31.1...v8.31.2"},{"type":"FIX","url":"https://github.com/gchq/CyberChef/issues/544"},{"type":"EVIDENCE","url":"https://github.com/gchq/CyberChef/issues/539"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gchq/cyberchef","events":[{"introduced":"0"},{"fixed":"e95dac82c2bc7bd769aad2ecb8202b9159efb763"},{"fixed":"01f0625d6a177f9c5df9281f12a27c814c2d8bcf"}],"database_specific":{"cpe":"cpe:2.3:a:gchq:cyberchef:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.31.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v8.31.1","v8.31.0","v8.30.1","v8.30.0","v8.29.1","v8.29.0","v8.28.0","v8.27.2","v8.27.1","v8.27.0","v8.26.3","v8.24.2","v8.26.2","v8.26.1","v8.26.0","v8.25.0","v8.24.3","v8.24.1","v8.24.0","v8.23.4","v8.23.3","v8.23.2","v8.23.1","v8.23.0","v8.22.1","v8.22.0","v8.21.0","v8.20.0","v8.19.7","v8.19.6","v8.19.5","v8.12.3","v8.19.4","v8.19.3","v8.19.2","v8.19.1","v8.19.0","v8.17.2","v8.18.1","v8.18.0","v8.17.1","v8.17.0","v8.16.1","v8.16.0","v8.15.1","v8.15.0","v8.14.0","v8.13.0","v8.12.4","v8.12.2","v8.12.1","v8.12.0","v8.11.2","v8.11.1","v8.11.0","v8.10.2","v8.10.1","v8.10.0","v8.9.2","v8.9.1","v8.9.0","v8.8.8","v8.8.7","v8.8.6","v8.8.5","v8.8.2","v8.8.4","v8.8.3","v8.8.1","v8.8.0","v8.7.0","v8.6.2","v8.6.1","v8.6.0","v8.5.1","v8.5.0","v8.4.3","v8.4.2","v8.4.1","v8.4.0","v8.3.1","v8.3.0","v8.2.0","v8.1.4","v8.1.3","v8.1.2","v8.1.1","v8.1.0","v8.0.2","v8.0.1","v8.0.0","v7.11.1","v7.11.0","v7.10.3","v7.10.2","v7.10.1","v7.10.0","v7.9.0","v7.8.1","v7.8.0","v7.7.8","v7.7.7","v7.7.6","v7.7.5","v7.7.4","v7.7.3","v7.7.2","v7.7.1","v7.7.0","v7.6.3","v7.6.2","v7.6.1","v7.6.0","v7.5.6","v7.5.5","v7.5.4","v7.5.3","v7.5.2","v7.5.0","v7.4.0","v7.3.0","v7.2.3","v7.2.2","v7.2.1","v7.2.0","v7.1.0","v7.0.0","v6.8.0","v6.7.2","v6.7.1","v6.7.0","v6.6.3","v6.6.2","v6.6.1","v6.6.0","v6.5.0","v6.4.6","v5.16.3","v6.4.5","v6.4.4","v6.3.1","v6.4.3","v6.4.2","v6.4.1","v6.3.2","v6.3.0","v6.2.1","v6.2.0","v6.1.0","v6.0.1","v5.20.0","v6.0.0","v5.19.3","v5.19.2","v5.19.1","v5.19.0","v5.18.1","v5.18.0","v5.17.0","v5.16.2","v5.16.1","v5.16.0","v5.15.0","v5.14.0","v5.13.1","v5.13.0","v5.12.4","v5.12.3","v5.12.1","v5.12.0","v5.11.7","v5.11.6","v5.11.5","v5.11.4","v5.11.3","v5.11.2","v5.11.1","v5.11.0","v5.10.7","v5.10.6","v5.10.5","v5.10.4","v5.10.3","v5.10.2","v5.10.1","v5.10.0","v5.9.2","v5.9.1","v5.9.0","v5.8.0","v5.7.3","v5.7.2","v5.7.1","v5.7.0","v5.6.0","v5.5.0","v5.4.1","v5.4.0","v5.3.5","v5.3.4","v5.3.3","v5.3.2","v5.3.1","v5.3.0","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.1","v5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15532.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}