{"id":"GHSA-82jf-8f24-xq9m","summary":"hexo-theme-anzhiyu Cross-site Scripting vulnerability","details":"Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.","aliases":["CVE-2024-25865"],"modified":"2025-03-31T13:36:59Z","published":"2024-03-03T00:30:32Z","database_specific":{"nvd_published_at":"2024-03-02T22:15:50Z","cwe_ids":["CWE-79","CWE-80"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-03-06T16:08:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25865"},{"type":"WEB","url":"https://github.com/anzhiyu-c/hexo-theme-anzhiyu/issues/200"},{"type":"PACKAGE","url":"https://github.com/anzhiyu-c/hexo-theme-anzhiyu"}],"affected":[{"package":{"name":"hexo-theme-anzhiyu","ecosystem":"npm","purl":"pkg:npm/hexo-theme-anzhiyu"},"versions":["1.6.12"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-82jf-8f24-xq9m/GHSA-82jf-8f24-xq9m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}