{"id":"GHSA-hw62-58pr-7wc5","summary":"DOM Expressions has a Cross-Site Scripting (XSS) vulnerability due to improper use of string.replace","details":"\u003e [!NOTE]  \n\u003e This advisory was originally emailed to community@solidjs.com by @nsysean.\n\nTo sum it up, the use of javascript's `.replace()` opens up to potential XSS vulnerabilities with the special replacement patterns beginning with `$`.\n\nParticularly, when the attributes of `Meta` tag from solid-meta are user-defined, attackers can utilise the special replacement patterns, either `$'` or `$\\`` to achieve XSS.\n\nThe solid-meta package has this issue since it uses `useAffect` and context providers, which injects the used assets in the html header. \"dom-expressions\" uses `.replace()` to insert the assets, which is vulnerable to the special replacement patterns listed above. \n\nThis effectively means that if the attributes of an asset tag contained user-controlled data, it would be vulnerable to XSS. For instance, there might be meta tags for the open graph protocol in a user profile page, but if attackers set the user query to some payload abusing `.replace()`, then they could execute arbitrary javascript in the victim's web browser. Moreover, it could be stored and cause more problems.","aliases":["CVE-2025-27108"],"modified":"2025-02-25T17:49:58Z","published":"2025-02-25T17:49:57Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-02-25T17:49:57Z","nvd_published_at":"2025-02-21T22:15:14Z","cwe_ids":["CWE-116","CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/ryansolid/dom-expressions/security/advisories/GHSA-hw62-58pr-7wc5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27108"},{"type":"WEB","url":"https://github.com/ryansolid/dom-expressions/commit/521f75dfa89ed24161646e7007d9d7d21da07767"},{"type":"PACKAGE","url":"https://github.com/ryansolid/dom-expressions"}],"affected":[{"package":{"name":"dom-expressions","ecosystem":"npm","purl":"pkg:npm/dom-expressions"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.39.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-hw62-58pr-7wc5/GHSA-hw62-58pr-7wc5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}