Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Linux Tipps & HardeningSecurity: Zwei Probleme in rootlesskit (Fedora)(30.09.2026 um 07:59 Uhr)
•
Unix & Linux ServerSecurity: Pufferüberlauf in libXrender (SUSE)(30.09.2026 um 07:59 Uhr)
•
Linux Tipps & HardeningSecurity: Pufferüberlauf in sngrep (Fedora)(30.09.2026 um 07:59 Uhr)
•
Linux Tipps & HardeningSecurity: Zwei Probleme in parted (Fedora)(30.09.2026 um 08:01 Uhr)
•••••••
Linux Tipps & HardeningSecurity: Zwei Probleme in rootlesskit (Fedora)(30.09.2026 um 07:59 Uhr)
•
Unix & Linux ServerSecurity: Pufferüberlauf in libXrender (SUSE)(30.09.2026 um 07:59 Uhr)
•
Linux Tipps & HardeningSecurity: Pufferüberlauf in sngrep (Fedora)(30.09.2026 um 07:59 Uhr)
•
Linux Tipps & HardeningSecurity: Zwei Probleme in parted (Fedora)(30.09.2026 um 08:01 Uhr)
•••••••
Intelligence View
⚡ tsecurity.de Intelligence

GHSA-CCGF-5RWJ-J3HV: GHSA-ccgf-5rwj-j3hv: DOM XSS via Unsafe Deserialization in TeleJSON

GHSA-ccgf-5rwj-j3hv: DOM XSS via Unsafe Deserialization in TeleJSON Vulnerability ID: GHSA-CCGF-5RWJ-J3HV CVSS Score: 5.1 Published: 2026-04-02 The telejson package prior to version 6.0.0 contains a DOM-based Cross-Site Scripting…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




GHSA-ccgf-5rwj-j3hv: DOM XSS via Unsafe Deserialization in TeleJSON




Vulnerability ID: GHSA-CCGF-5RWJ-J3HV

CVSS Score: 5.1

Published: 2026-04-02




The telejson package prior to version 6.0.0 contains a DOM-based Cross-Site Scripting (XSS) vulnerability. The package deserializer uses an unsanitized object property, _constructor-name_, within a dynamically generated function via new Function(). Attackers can supply crafted JSON payloads to achieve arbitrary JavaScript execution in the context of the vulnerable application.






TL;DR



TeleJSON < 6.0.0 passes unvalidated input from the _constructor-name_ JSON property into a new Function() call during deserialization. This allows attackers to achieve arbitrary code execution via crafted JSON payloads, often delivered through cross-frame messaging.









⚠️ Exploit Status: POC






Technical Details





  • Vulnerability Type: DOM-based Cross-Site Scripting (XSS)


  • CWE ID: CWE-79, CWE-94


  • Attack Vector: Network


  • Privileges Required: None


  • CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N


  • Primary Mitigation: Upgrade to telejson >= 6.0.0






Affected Systems




  • Frontend applications utilizing the telejson library.

  • Storybook instances and custom addons communicating via window.postMessage.


  • telejson: < 6.0.0 (Fixed in: 6.0.0)






Mitigation Strategies




  • Upgrade telejson dependency to version 6.0.0 or higher.

  • Implement strong origin validation for any postMessage event listeners processing incoming JSON payloads.

  • Deploy a restrictive Content Security Policy (CSP) that omits the 'unsafe-eval' directive.



Remediation Steps:




  1. Audit project dependencies using npm audit or yarn audit to identify vulnerable versions of telejson.

  2. Update telejson to version 6.0.0.

  3. Review application code that utilizes telejson.parse(). If custom prototype restoration is required, explicitly pass { allowFunction: true } in the options object.

  4. Review all window.addEventListener('message', ...) implementations. Ensure event.origin is rigorously validated against a trusted whitelist before allowing the payload to reach parsing logic.






References








Read the full report for GHSA-CCGF-5RWJ-J3HV on our website for more details including interactive diagrams and full exploit analysis.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten GHSA-CCGF-5RWJ-J3HV: GHSA-ccgf-5rwj-j3hv: DOM XSS via Unsafe Deserialization in TeleJSON

Thematisch verwandte Begriffe: GHSACCGF5RWJJ3HV, GHSAccgf5rwjj3hv, Unsafe, Deserialization · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-81433 | A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag