GHSA-j9m2-6hq2-4r3c

    Dashboard / Vulnerabilities / GHSA-j9m2-6hq2-4r3c

    GHSA-j9m2-6hq2-4r3c

    Published: 16 Jul 2019Last Modified: 10 Sept 2026

    Summary: Cross-site Scripting in invenio-previewer

    Details: ## Cross-Site Scripting (XSS) vulnerability in JSON, Markdown and iPython Notebook previewers ### Impact Several Cross-Site Scripting (XSS) vulnerabilities have been found in the JSON, Markdown and iPython Notebook previewers. The vulnerabilities would allow a malicous user to upload a JSON, Markdown or Notebook file with embedded scripts that would be executed by a victims browser. ### Patches Invenio-Previewer v1.0.0a12 fixes the issue. ### Workarounds You can remediate the vulnerability without upgrading by disabling the affected previewers. You do this by adding the following to your configuration: ```python PREVIEWER_PREFERENCE = [ 'csv_dthreejs', 'simple_image', # 'json_prismjs', 'xml_prismjs', # 'mistune', 'pdfjs', # 'ipynb', 'zip', ] ``` Afterwards, you should not be able to preview JSON, Markdown or iPython Notebook files. ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: invenio-previewer

    Purl: pkg:pypi/invenio-previewer

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.0a12

    Affected versions

    0.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High