Reflected Cross-Site Scripting Vulnerability in wabac.js by Webrecorder
CVE-2025-58765
What is CVE-2025-58765?
The wabac.js library, which facilitates a web archive replay system using Service Workers, contains a vulnerability in its 404 error handling logic. Specifically, in versions 2.23.10 and earlier, the 'requestURL' parameter is directly inserted into an inline script without proper sanitization. This flaw permits attackers to create malicious URLs capable of executing arbitrary JavaScript in the user’s browser, posing significant security threats depending on the implementation of CORS policies. Users are advised to update to version 2.23.11 to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wabac.js < 2.23.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
