PT-2025-36954 · Wabac.Js · Wabac.Js
Dedal0
·
Published
2025-09-09
·
Updated
2025-09-10
·
CVE-2025-58765
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
wabac.js versions 2.23.10 and below
Description:
wabac.js provides a full web archive replay system using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic. The
requestURL parameter, derived from the original request target, is directly embedded into an inline <script> block without sanitization or escaping, allowing an attacker to execute arbitrary JavaScript in the victim’s browser. The scope may be limited by CORS policies.Recommendations:
Update wabac.js to version 2.23.11 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wabac.Js