CVE-2023-45815

    Dashboard / Vulnerabilities / CVE-2023-45815

    CVE-2023-45815

    Published: 19 Oct 2023Last Modified: 12 Aug 2026

    Summary: ArchiveBox: Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context

    Details: ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same browser session and view an archived malicious page designed to target your ArchiveBox instance. Malicious Javascript could potentially act using your logged-in admin credentials and add/remove/modify snapshots, add/remove/modify ArchiveBox users, and generally do anything an admin user could do. The impact is less severe for non-logged-in users, as malicious Javascript cannot *modify* any archives, but it can still *read* all the other archived content by fetching the snapshot index and iterating through it. Because all of ArchiveBox's archived content is served from the same host and port as the admin panel, when archived pages are viewed the JS executes in the same context as all the other archived pages (and the admin panel), defeating most of the browser's usual CORS/CSRF security protections and leading to this issue. Version 0.9.0 contains a patch. As a mitigation for this issue would be to disable the wget extractor by setting `archivebox config --set SAVE_WGET=False`, ensure you are always logged out, or serve only a [static HTML version](https://github.com/ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive#2-export-and-host-it-as-static-html) of your archive.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v0.8.6rc0
    v0.8.5rc51
    v0.8.5rc53
    v0.8.5rc50
    v0.8.5rc49
    v0.8.5rc48
    v0.8.5rc47
    v0.8.5rc46
    v0.8.5rc45
    v0.8.5rc44
    v0.8.5rc43
    v0.8.5rc42
    v0.8.5rc41
    v0.8.5rc40
    v0.8.5rc39
    v0.8.5rc38
    v0.8.5rc37
    v0.8.5rc36
    v0.8.5rc35
    v0.8.5rc34
    v0.8.5rc33
    v0.8.5rc32
    v0.8.5rc31
    v0.8.5rc30
    v0.8.5rc29
    v0.8.5rc28
    v0.8.5rc27
    v0.8.5rc26
    v0.8.5rc25
    v0.8.5rc24
    v0.8.5rc23
    v0.8.5rc22
    v0.8.5rc13
    v0.8.5rc12
    v0.8.5rc11
    v0.8.5rc10
    v0.8.5rc9
    v0.8.5rc8
    v0.8.5rc6
    v0.8.5rc5
    v0.8.5rc4
    v0.8.5rc3
    v0.8.5rc2
    v0.8.5-rc
    v0.8.4-rc
    v0.8.3-rc
    v0.8.2-rc
    v0.8.0-rc

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-45815 | CVE-DB