Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Webbertakken

Researcher fromGitHub, Inc.
#22548of 53,622
10Total CVSS
Vulnerabilities · 1
PT-2025-28964
10
2025-07-09
Unknown · Docusaurus-Plugin-Content-Gists · CVE-2025-53624
Name of the Vulnerable Software and Affected Versions: docusaurus-plugin-content-gists versions prior to 4.0.0 Description: The Docusaurus gists plugin displays public gists of a GitHub user on a Docusaurus instance. Versions prior to 4.0.0 inadvertently include GitHub Personal Access Tokens in client-side JavaScript bundles when passed through plugin configuration options. These tokens, intended for build-time API access, become accessible to anyone who can view the website's source code. Recommendations: Update docusaurus-plugin-content-gists to version 4.0.0.