{"id":"GHSA-w765-jm6w-4hhj","summary":"Webrecorder packages are vulnerable to XSS through 404 error handling logic","details":"A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter `requestURL` (derived from the original request target) is directly embedded into an inline `\u003cscript\u003e` block without sanitization or escaping.\n\nThis allows an attacker to craft a malicious URL that executes arbitrary JavaScript in the victim’s browser.\n\nThe scope may be limited by CORS policies, depending on the situation in which wabac.js is used.\n\n### Patches\n\nThe vulnerability is fixed in wabac.js v2.23.11.","aliases":["CVE-2025-58765"],"modified":"2025-09-10T17:13:45Z","published":"2025-09-10T17:13:45Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-09-10T17:13:45Z","nvd_published_at":"2025-09-09T21:15:38Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/webrecorder/wabac.js/security/advisories/GHSA-w765-jm6w-4hhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58765"},{"type":"WEB","url":"https://github.com/webrecorder/archiveweb.page/pull/315"},{"type":"WEB","url":"https://github.com/webrecorder/replayweb.page/pull/448"},{"type":"WEB","url":"https://github.com/webrecorder/wabac.js/commit/25feb4a5af69a6b65694426eae67b890be438c4c"},{"type":"WEB","url":"https://github.com/webrecorder/replayweb.page/releases/tag/v2.3.17"},{"type":"PACKAGE","url":"https://github.com/webrecorder/wabac.js"},{"type":"WEB","url":"https://github.com/webrecorder/wabac.js/releases/tag/v2.23.11"}],"affected":[{"package":{"name":"@webrecorder/wabac","ecosystem":"npm","purl":"pkg:npm/%40webrecorder/wabac"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.23.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"}},{"package":{"name":"replaywebpage","ecosystem":"npm","purl":"pkg:npm/replaywebpage"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.3.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"}},{"package":{"name":"@webrecorder/archivewebpage","ecosystem":"npm","purl":"pkg:npm/%40webrecorder/archivewebpage"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.15.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-w765-jm6w-4hhj/GHSA-w765-jm6w-4hhj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"}]}