Vulnerability GHSA-h4hv-92pp-pcjg
High Risk
HIGH RISK
CVSS Score: 7.2
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 29, 2026 at 06:33 AM UTC
CyberChef has a Cross-site Scripting issue
4.0.0 - 10.24.0
4.0.0 - 10.24.0
Summary
CyberChef has a Cross-site Scripting issue
Details
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 days ago
CyberChef: Prototype pollution in Series Chart operation
4.0.0 - 11.1.0 GHSA-fx6f-382r-j72c
4.0.0 - 11.1.0 GHSA-fx6f-382r-j72c
Medium Risk
7 years ago
Cross-Site Scripting in cyberchef
4.0.0 - 8.31.1 GHSA-jp6r-xcjj-5h7r
4.0.0 - 8.31.1 GHSA-jp6r-xcjj-5h7r
Impacted packages
Timeline
Published
5 months ago
April 29, 2026 at 06:33 AM UTC
Fixed (11.0.0)
5 months ago
April 28, 2026 at 03:03 PM UTC
Last Modified
4 months ago
May 06, 2026 at 10:26 PM UTC