{"id":"CVE-2020-8176","details":"A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.","aliases":["GHSA-jqh7-w5pr-cr56"],"modified":"2026-07-09T00:13:55.537038Z","published":"2020-07-02T19:15:12.590Z","references":[{"type":"REPORT","url":"https://hackerone.com/reports/881409"},{"type":"FIX","url":"https://github.com/Shopify/quilt/pull/1455"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/shopify/quilt","events":[{"introduced":"e0d52556170e26a8bd8a1d5f42c5c4247fe72482"},{"last_affected":"153d270592373acc0d835625e2824599480cdbd0"}],"database_specific":{"cpe":["cpe:2.3:a:shopify:koa-shopify-auth:3.1.61:*:*:*:*:*:*:*","cpe:2.3:a:shopify:koa-shopify-auth:3.1.62:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.1.61"},{"last_affected":"3.1.61"},{"introduced":"3.1.62"},{"last_affected":"3.1.62"}],"source":"CPE_STRING"}}],"versions":["3.1.61","3.1.62","@shopify/web-worker@1.3.8","@shopify/react-web-worker@1.2.18","@shopify/react-server-webpack-plugin@3.0.3","@shopify/polyfills@1.1.10","@shopify/magic-entries-webpack-plugin@0.1.2","@shopify/koa-shopify-auth@3.1.62","@shopify/browser@1.0.0","@shopify/web-worker@1.3.7","@shopify/react-web-worker@1.2.17","@shopify/react-server-webpack-plugin@3.0.2","@shopify/polyfills@1.1.9","@shopify/magic-entries-webpack-plugin@0.1.1","v1.12.2","v1.12.1","@shopify/react-web-worker@1.2.16","@shopify/react-universal-provider@1.1.15","@shopify/react-tracking-pixel@3.0.46","@shopify/react-server@0.12.1","@shopify/react-server-webpack-plugin@3.0.1","@shopify/react-import-remote@1.0.41","@shopify/react-i18n@3.0.2","@shopify/react-i18n-universal-provider@1.0.55","@shopify/react-hydrate@1.1.23","@shopify/react-html@9.3.10","@shopify/react-hooks@1.10.0","@shopify/react-graphql@6.1.9","@shopify/react-graphql-universal-provider@3.1.9","@shopify/react-google-analytics@3.1.13","@shopify/react-form@0.6.2","@shopify/react-csrf-universal-provider@1.1.15","@shopify/react-cookie@0.0.26","@shopify/react-async@3.1.17","@shopify/react-app-bridge-universal-provider@1.0.30","@shopify/react-google-analytics@3.1.12","@shopify/react-form-state@0.11.23","@shopify/enzyme-utilities@2.1.11","@shopify/react-google-analytics@3.1.11","@shopify/react-form-state@0.11.22","@shopify/enzyme-utilities@2.1.10","@shopify/react-server@0.12.0","@shopify/react-server-webpack-plugin@3.0.0","@shopify/react-router@0.0.24","@shopify/react-performance@1.3.4","@shopify/performance@1.2.8","@shopify/koa-performance@1.2.4","@shopify/magic-entries-webpack-plugin@0.1.0","@shopify/react-server@0.11.0","@shopify/react-server-webpack-plugin@2.2.34","@shopify/koa-shopify-graphql-proxy@4.0.0","@shopify/koa-shopify-auth@3.1.61"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8176.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}