{"id":"GHSA-7jh9-6cpf-h4m7","summary":"XSS in hello.js","details":"This affects the package hello.js before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as `javascript:alert(1)`.","aliases":["CVE-2020-7741","SNYK-JS-HELLOJS-1014546"],"modified":"2026-07-08T06:49:36.561801408Z","published":"2021-01-13T19:07:01Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-01-13T19:06:37Z","nvd_published_at":"2020-10-06T15:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7741"},{"type":"WEB","url":"https://github.com/MrSwitch/hello.js/commit/d6f5137f30de6e0ef7048191ee6ae575fdc2f669"},{"type":"WEB","url":"https://github.com/MrSwitch/hello.js/blob/3b79ec93781b3d7b9c0b56f598e060301d1f3e73/dist/hello.all.js%23L1545"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-HELLOJS-1014546"}],"affected":[{"package":{"name":"hellojs","ecosystem":"npm","purl":"pkg:npm/hellojs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-7jh9-6cpf-h4m7/GHSA-7jh9-6cpf-h4m7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H"}]}