{"id":"GHSA-fm8c-6m29-rp6j","summary":"repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard","details":"### Impact\nThe `RepoCard` component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React's `dangerouslySetInnerHTML` to render the repository name (`repo` prop) during the loading state without any sanitization. \n\nIf a developer using this package passes unvalidated user input directly into the `repo` prop (for example, reading it from a URL query parameter), an attacker can execute arbitrary JavaScript in the context of the user's browser.\n\n### Proof of Concept\n```jsx\nimport { RepoCard } from 'repostat';\n\nfunction App() {\n  const params = new URLSearchParams(window.location.search);\n  const maliciousRepo = params.get('repo') || 'facebook/react';\n\n  return \u003cRepoCard repo={maliciousRepo} token=\"YOUR_TOKEN\" /\u003e;\n}\n```\n\n### Remediation\nUpdate to version 1.0.1. The use of dangerouslySetInnerHTML has been removed, and the repo prop is now safely rendered using standard React JSX data binding, which automatically escapes HTML entities.","aliases":["CVE-2026-27612"],"modified":"2026-02-25T16:26:21.121272Z","published":"2026-02-25T16:04:41Z","database_specific":{"github_reviewed_at":"2026-02-25T16:04:41Z","nvd_published_at":"2026-02-25T03:16:05Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/denpiligrim/repostat/security/advisories/GHSA-fm8c-6m29-rp6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27612"},{"type":"WEB","url":"https://github.com/denpiligrim/repostat/commit/715df5f73359d222fd7876e948d14290180e3c88"},{"type":"PACKAGE","url":"https://github.com/denpiligrim/repostat"}],"affected":[{"package":{"name":"repostat","ecosystem":"npm","purl":"pkg:npm/repostat"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-fm8c-6m29-rp6j/GHSA-fm8c-6m29-rp6j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}