Showing 1 vulnerability on this page for docusaurus-plugin-content-gists

Signals CISA KEV Ransomware Nuclei
npm vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

docusaurus-plugin-content-gists Exposes GitHub Personal Access Token

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token, intended for build-time API access only, is inadvertently included in client-side JavaScript bundles, making it accessible to anyone who can view the website's source code. This vul

CWE-200Jul 9, 20251 related artifact
CVSS10.0v3.1EPSS1.84%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX