{"id":"GHSA-33vc-wfww-vjfv","summary":"jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin","details":"### Vulnerability in jsondiffpatch\n\nVersions of `jsondiffpatch` prior to `0.7.2` are vulnerable to Cross-site Scripting (XSS) in the `HtmlFormatter` (`HtmlFormatter::nodeBegin`). When diffs are rendered to HTML using the built-in formatter, untrusted payloads can inject scripts and execute in the context of a consuming web page.\n\n**Affected versions:** \u003e= 0, \u003c 0.7.2\n**Patched version:** 0.7.2\n\n**Remediation**\nUpgrade to `jsondiffpatch` `0.7.2` or later. The fix hardens the HTML formatter to avoid script injection.\n\n**Workarounds**\nAvoid using the HTML formatter on untrusted diffs, or sanitize/escape the rendered output.","aliases":["CVE-2025-9910"],"modified":"2026-09-10T03:50:27.847806501Z","published":"2025-09-11T06:30:23Z","database_specific":{"github_reviewed_at":"2025-09-12T21:12:49Z","nvd_published_at":"2025-09-11T05:15:34Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9910"},{"type":"WEB","url":"https://github.com/benjamine/jsondiffpatch/issues/383"},{"type":"WEB","url":"https://github.com/benjamine/jsondiffpatch/commit/0e374b5dd8d7879b329a9fc18affbd46ad50dd14"},{"type":"WEB","url":"https://benjamine.github.io/jsondiffpatch/index.html"},{"type":"PACKAGE","url":"https://github.com/benjamine/jsondiffpatch"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-12549277"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-12549276"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-JSONDIFFPATCH-10369031"}],"affected":[{"package":{"name":"jsondiffpatch","ecosystem":"npm","purl":"pkg:npm/jsondiffpatch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-33vc-wfww-vjfv/GHSA-33vc-wfww-vjfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}