CVE-2025-9910
ADVISORY - githubSummary
Vulnerability in jsondiffpatch
Versions of jsondiffpatch prior to 0.7.2 are vulnerable to Cross-site Scripting (XSS) in the HtmlFormatter (HtmlFormatter::nodeBegin). When diffs are rendered to HTML using the built-in formatter, untrusted payloads can inject scripts and execute in the context of a consuming web page.
Affected versions: >= 0, < 0.7.2 Patched version: 0.7.2
Remediation
Upgrade to jsondiffpatch 0.7.2 or later. The fix hardens the HTML formatter to avoid script injection.
Workarounds Avoid using the HTML formatter on untrusted diffs, or sanitize/escape the rendered output.
Common Weakness Enumeration (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NIST
1.6
CVSS SCORE
1.3lowGitHub
1.6
CVSS SCORE
5.3mediumChainguard
CGA-3rvj-mwjp-rcfw
-
Chainguard
CGA-6vhx-w6mp-365j
-
Chainguard
CGA-7mh2-3rph-xj4g
-
Chainguard
CGA-7r66-j8v9-9qr4
-
Chainguard
CGA-q6w8-87c5-j7jq
-
Chainguard
CGA-v2wj-93xr-mjq5
-
minimos
MINI-5vcf-2p87-rmx8
-
minimos
MINI-8x9p-573x-mjmf
-
minimos
MINI-9rjc-989r-c698
-
minimos
MINI-f3cj-33w9-qff9
-
minimos
MINI-hc79-xgh8-j74q
-
minimos
MINI-p985-j29q-xwm6
-
minimos
MINI-rr7h-4j8f-r9xf
-