PT-2025-37115 · Unknown · Jsondiffpatch

Zendive

·

Published

2025-09-11

·

Updated

2026-01-06

·

CVE-2025-9910

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: jsondiffpatch versions prior to 0.7.2
Description: The package is susceptible to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads, potentially leading to code execution if untrusted payloads are used as a source for the diff and the result is rendered using the built-in html formatter on a private website.
Recommendations: Update to version 0.7.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-9910
GHSA-33VC-WFWW-VJFV

Affected Products

Jsondiffpatch