CVE-2020-7741
CRITICALhello.js < 1.18.6 - Cross-Site Scripting via oauth_redirect URL Parameter
Title source: llmDescription
This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-HELLOJS-1014546
Broken Link x_refsource_misc
https://github.com/MrSwitch/hello.js/blob/3b79ec93781b3d7b9c0b56f598e060301d1f3e73/dist/hello.all.js%23L1545
Patch, Third Party Advisory x_refsource_misc
https://github.com/MrSwitch/hello.js/commit/d6f5137f30de6e0ef7048191ee6ae575fdc2f669
Scores
CVSS v3
9.9
EPSS
0.0146
EPSS Percentile
70.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Details
CWE
CWE-79
Status
published
Products (2)
hello.js_project/hello.js
< 1.18.6
npm/hellojs
0 - 1.18.6npm
Published
Oct 06, 2020
Tracked Since
Feb 18, 2026