PT-2026-21840 · Repostat · Repostat

Denpiligrim

·

Publicado

2026-02-25

·

Atualizado

2026-02-25

·

CVE-2026-27612

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Repostat versions prior to 1.0.1
Description Repostat, a React component used to display GitHub repository information, contains a Reflected Cross-Site Scripting (XSS) issue. The RepoCard component previously used dangerouslySetInnerHTML to render the repository name (repo prop) during the loading state without proper sanitization. This allowed for the execution of arbitrary JavaScript in a user's browser if an attacker could control the input passed into the repo prop. The issue was addressed in version 1.0.1 by removing the use of dangerouslySetInnerHTML and utilizing standard React JSX data binding for safe rendering.
Recommendations Update Repostat to version 1.0.1 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27612
GHSA-FM8C-6M29-RP6J

Produtos afetados

Repostat