PT-2026-21840 · Repostat · Repostat
Denpiligrim
·
Publicado
2026-02-25
·
Atualizado
2026-02-25
·
CVE-2026-27612
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Repostat versions prior to 1.0.1
Description
Repostat, a React component used to display GitHub repository information, contains a Reflected Cross-Site Scripting (XSS) issue. The
RepoCard component previously used dangerouslySetInnerHTML to render the repository name (repo prop) during the loading state without proper sanitization. This allowed for the execution of arbitrary JavaScript in a user's browser if an attacker could control the input passed into the repo prop. The issue was addressed in version 1.0.1 by removing the use of dangerouslySetInnerHTML and utilizing standard React JSX data binding for safe rendering.Recommendations
Update Repostat to version 1.0.1 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Repostat