Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9965-vmph-33xx | validator.js has a URL validation bypass vulnerability in its isURL function |
Sat, 18 Oct 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Validator Project
Validator Project validator |
|
| CPEs | cpe:2.3:a:validator_project:validator:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Validator Project
Validator Project validator |
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Validatorjs
Validatorjs validator.js |
|
| Vendors & Products |
Validatorjs
Validatorjs validator.js |
Tue, 30 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 30 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-30T19:36:11.737Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56200
Updated: 2025-09-30T19:35:36.845Z
Status : Analyzed
Published: 2025-09-30T18:15:50.307
Modified: 2025-10-18T01:48:26.373
Link: CVE-2025-56200
No data.
OpenCVE Enrichment
Updated: 2025-10-02T08:48:20Z
Github GHSA