{"id":"GHSA-pxpf-v376-7xx5","summary":"tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload","details":"This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the cross-site scripting (XSS) payload.","aliases":["CVE-2022-25854","SNYK-JS-YAIREOTAGIFY-2404358"],"modified":"2026-07-08T06:49:35.540099993Z","published":"2022-04-30T00:00:33Z","database_specific":{"github_reviewed_at":"2022-05-03T04:55:32Z","nvd_published_at":"2022-04-29T20:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25854"},{"type":"WEB","url":"https://github.com/yairEO/tagify/issues/988"},{"type":"WEB","url":"https://github.com/yairEO/tagify/commit/198c0451fad188390390395ccfc84ab371def4c7"},{"type":"WEB","url":"https://bsg.tech/blog/cve-2022-25854-stored-xss-in-yaireo-tagify-npm-module"},{"type":"PACKAGE","url":"https://github.com/yairEO/tagify"},{"type":"WEB","url":"https://github.com/yairEO/tagify/releases/tag/v4.9.8"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-YAIREOTAGIFY-2404358"}],"affected":[{"package":{"name":"@yaireo/tagify","ecosystem":"npm","purl":"pkg:npm/%40yaireo/tagify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.9.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-pxpf-v376-7xx5/GHSA-pxpf-v376-7xx5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}