{"id":"GHSA-p5g4-v748-6fh8","summary":"tarteaucitron.js allows url scheme injection via unfiltered inputs","details":"A vulnerability was identified in `tarteaucitron.js`, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as `javascript:alert()`. Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link.\n\n## Impact\nAn attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to:\n- Execution of arbitrary JavaScript code\n- Theft of sensitive data through phishing attacks\n- Modification of the user interface behavior\n\n## Fix https://github.com/AmauriC/tarteaucitron.js/commit/2fa1e01023bce2e4b813200600bb1619d56ceb02\nThe issue was resolved by enforcing strict URL validation, ensuring that they start with `http://` or `https://` before being used.","aliases":["CVE-2025-31476","DRUPAL-CONTRIB-2025-027"],"modified":"2025-12-10T23:41:04.304780Z","published":"2025-04-07T16:46:57Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-07T16:46:57Z","nvd_published_at":"2025-04-07T15:15:44Z"},"references":[{"type":"WEB","url":"https://github.com/AmauriC/tarteaucitron.js/security/advisories/GHSA-p5g4-v748-6fh8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31476"},{"type":"WEB","url":"https://github.com/AmauriC/tarteaucitron.js/commit/2fa1e01023bce2e4b813200600bb1619d56ceb02"},{"type":"PACKAGE","url":"https://github.com/AmauriC/tarteaucitron.js"}],"affected":[{"package":{"name":"tarteaucitronjs","ecosystem":"npm","purl":"pkg:npm/tarteaucitronjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.20.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-p5g4-v748-6fh8/GHSA-p5g4-v748-6fh8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}