{"id":"CVE-2021-43842","details":"Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal `\u003cimg\u003e` tags. Commit 5d3e81496fba1f0fbd64eeb855f30f69a9040718 fixes this vulnerability by adding an optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users. Wiki.js version 2.5.260 is the first production version to contain a patch. Version 2.5.258 is the first development build to contain a patch and is available only as a Docker image as requarks/wiki:canary-2.5.258.","aliases":["GHSA-3qv4-gp35-rgh7"],"modified":"2026-07-08T06:27:52.894653902Z","published":"2021-12-20T23:15:29.300Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"2.5.257"}],"source":"CPE_RANGE","vendor_product":"requarks:wiki.js","cpes":["cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://github.com/Requarks/wiki/releases/tag/2.5.260"},{"type":"FIX","url":"https://github.com/Requarks/wiki/commit/5d3e81496fba1f0fbd64eeb855f30f69a9040718"},{"type":"FIX","url":"https://github.com/Requarks/wiki/security/advisories/GHSA-3qv4-gp35-rgh7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/requarks/wiki","events":[{"introduced":"0"},{"fixed":"5d3e81496fba1f0fbd64eeb855f30f69a9040718"},{"fixed":"e79e591f9e3268089fbf4029876c6cedb26a2055"}],"database_specific":{"source":"REFERENCES"}}],"versions":["2.5.255","2.5.254","2.5.219","2.5.214","2.5.201","2.5.197","2.5.191","2.5.170","2.5.159","2.5.144","2.5.136","2.5.132","2.5.126","2.5.121","2.5.117","2.5.105","2.4.107","2.4.105","2.4.75","2.3.77","2.3.72","2.3.71","2.2.51","2.2.50","2.1.113","2.0.12","2.0.1","2.0.0-rc.17","2.0.0-rc.1","2.0.0-beta.303","2.0.0-beta.275","2.0.0-beta.268","2.0.0-beta.267","2.0.0-beta.241","2.0.0-beta.230","2.0.0-beta.208","2.0.0-beta.203","2.0.0-beta.180","2.0.0-beta.174","2.0.0-beta.148","2.0.0-beta.147","2.0.0-beta.115","2.0.0-beta.91","2.0.0-beta.84","2.0.0-beta.68","2.0.0-beta.42","2.0.0-beta.11","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.0-beta.13","v1.0.0-beta.12","v1.0.0-beta.11","v1.0.0-beta.10","v1.0.0-beta.9","v1.0.0-beta.8","v1.0.0-beta.7","v1.0.0-beta.6","v1.0-beta.5","v1.0-beta.4","v1.0-beta.3","v1.0-beta.2","v1.0-beta.1","v1.0-alpha.7","v1.0-alpha.6","v1.0-alpha.5","v1.0-alpha.4","v1.0-alpha.3","v1.0-alpha.2","v1.0-alpha.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43842.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}