{"id":"GHSA-h6gj-6jjq-h8g9","summary":"jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label","details":"### Impact\nInitializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call `.checkboxradio( \"refresh\" )` on such a widget and the initial HTML contained encoded HTML entities, they will erroneously get decoded. This can lead to potentially executing JavaScript code.\n\nFor example, starting with the following initial secure HTML:\n```html\n\u003clabel\u003e\n\t\u003cinput id=\"test-input\"\u003e\n\t&lt;img src=x onerror=\"alert(1)\"&gt;\n\u003c/label\u003e\n```\nand calling:\n```js\n$( \"#test-input\" ).checkboxradio();\n$( \"#test-input\" ).checkboxradio( \"refresh\" );\n```\nwill turn the initial HTML into:\n```html\n\u003clabel\u003e\n\t\u003c!-- some jQuery UI elements --\u003e\n\t\u003cinput id=\"test-input\"\u003e\n\t\u003cimg src=x onerror=\"alert(1)\"\u003e\n\u003c/label\u003e\n```\nand the alert will get executed.\n\n### Patches\nThe bug has been patched in jQuery UI 1.13.2.\n\n### Workarounds\nTo remediate the issue, if you can change the initial HTML, you can wrap all the non-input contents of the `label` in a `span`:\n```html\n\u003clabel\u003e\n\t\u003cinput id=\"test-input\"\u003e\n\t\u003cspan\u003e&lt;img src=x onerror=\"alert(1)\"&gt;\u003c/span\u003e\n\u003c/label\u003e\n```\n\n### References\nhttps://blog.jqueryui.com/2022/07/jquery-ui-1-13-2-released/\n\n### For more information\nIf you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues?q=is%3Aissue+is%3Aopen+sort%3Aupdated-desc). If you don't find an answer, open a new issue.","aliases":["CVE-2022-31160"],"modified":"2025-07-21T19:01:07.439663Z","published":"2022-07-18T17:07:36Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-18T17:07:36Z","nvd_published_at":"2022-07-20T20:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31160"},{"type":"WEB","url":"https://github.com/jquery/jquery-ui/commit/8cc5bae1caa1fcf96bf5862c5646c787020ba3f9"},{"type":"WEB","url":"https://blog.jqueryui.com/2022/07/jquery-ui-1-13-2-released"},{"type":"WEB","url":"https://github.com/jquery-ui-rails/jquery-ui-rails/blob/master/VERSIONS.md"},{"type":"WEB","url":"https://github.com/jquery-ui-rails/jquery-ui-rails/releases/tag/v8.0.0-release"},{"type":"PACKAGE","url":"https://github.com/jquery/jquery-ui"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-ui-rails/CVE-2022-31160.yml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/12/msg00015.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6XBR3G3JR5ZIOJDO4224M3INXDS2VFDD"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J5LGNTICB5BRFAG3DHVVELS6H3CZSQMO"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QB2FJQXCNHO32VGVOC6DY6IPGVE4VDU6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220909-0007"},{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2022-052"}],"affected":[{"package":{"name":"jquery-ui","ecosystem":"npm","purl":"pkg:npm/jquery-ui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h6gj-6jjq-h8g9/GHSA-h6gj-6jjq-h8g9.json"}},{"package":{"name":"org.webjars.npm:jquery-ui","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.2"}]}],"versions":["1.10.4","1.10.5","1.12.0","1.12.0-rc.2","1.12.1","1.13.0","1.13.0-rc.2","1.13.0-rc.3","1.13.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h6gj-6jjq-h8g9/GHSA-h6gj-6jjq-h8g9.json"}},{"package":{"name":"jquery-ui-rails","ecosystem":"RubyGems","purl":"pkg:gem/jquery-ui-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.0"}]}],"versions":["0.0.1","0.0.2","0.1.0","0.2.0","0.2.1","0.2.2","0.3.0","0.4.0","0.4.1","0.5.0","1.0.0","1.1.0","1.1.1","2.0.0","2.0.1","2.0.2","3.0.0","3.0.1","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.1.0","4.1.1","4.1.2","4.2.0","4.2.1","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","6.0.0","6.0.1","7.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h6gj-6jjq-h8g9/GHSA-h6gj-6jjq-h8g9.json"}},{"package":{"name":"jQuery.UI.Combined","ecosystem":"NuGet","purl":"pkg:nuget/jQuery.UI.Combined"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.2"}]}],"versions":["1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.11.0","1.11.1","1.11.2","1.11.3","1.11.4","1.12.0","1.12.1","1.13.0","1.13.1","1.8.10","1.8.11","1.8.12","1.8.13","1.8.14","1.8.15","1.8.16","1.8.17","1.8.18","1.8.19","1.8.20","1.8.20.1","1.8.21","1.8.22","1.8.23","1.8.24","1.8.9","1.9.0","1.9.0-RC1","1.9.1","1.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h6gj-6jjq-h8g9/GHSA-h6gj-6jjq-h8g9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}