CVE-2021-25987
Hexo Vulnerable to XSS
4.6
MEDIUM
CVSS 3.1
EPSS 0.09%
Description
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
How to fix CVE-2021-25987
To remediate CVE-2021-25987, upgrade the affected package to a fixed version below.
- npm/hexo—upgrade to 6.0.0 or later
Is CVE-2021-25987 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.0.1, < 6.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.6 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |