Excalidraw Vulnerable to Cross-site Scripting (XSS) via Embedded Links in Whiteboard Objects
CVE-2023-26140

6.1MEDIUM

Key Information:

Vendor

Excalidraw

Vendor
CVE Published:
16 August 2023

What is CVE-2023-26140?

Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.

Affected Version(s)

@excalidraw/excalidraw 0.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eugene Lim
The MOps Team
.