Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18905 | OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer |
Github GHSA |
GHSA-2hw3-h8qx-hqqp | OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer |
Mon, 23 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file preview/browsing feature of the application, where files with a .py extension that contain JavaScript code wrapped in <script> tags may be interpreted and executed as HTML in certain modes. This leads to a stored XSS vulnerability. This issue has been patched in version 4.0.0-rc.4. | |
| Title | OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-23T16:57:37.085Z
Reserved: 2025-06-13T19:17:51.726Z
Link: CVE-2025-50183
Updated: 2025-06-23T16:57:30.755Z
Status : Deferred
Published: 2025-06-19T03:15:25.717
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-50183
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA