{"id":"GHSA-qpqh-46qj-vwcw","summary":"Cross-site Scripting in docsify","details":"docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.","aliases":["CVE-2020-7680","SNYK-JS-DOCSIFY-567099"],"modified":"2026-09-10T03:49:14.824566862Z","published":"2021-05-18T01:53:18Z","database_specific":{"nvd_published_at":"2020-07-20T16:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-05-10T21:00:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7680"},{"type":"WEB","url":"https://github.com/docsifyjs/docsify/issues/1126"},{"type":"WEB","url":"https://github.com/docsifyjs/docsify/pull/1128"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-DOCSIFY-567099"},{"type":"WEB","url":"http://packetstormsecurity.com/files/158515/Docsify.js-4.11.4-Cross-Site-Scripting.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/161495/docsify-4.11.6-Cross-Site-Scripting.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2021/Feb/71"}],"affected":[{"package":{"name":"docsify","ecosystem":"npm","purl":"pkg:npm/docsify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.11.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-qpqh-46qj-vwcw/GHSA-qpqh-46qj-vwcw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}