CVE-2023-1767

MEDIUM

Snyk Advisor <28th March 2023 - XSS

Title source: llm
STIX 2.1

Description

The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on its package health page. An attacker could create a package in NPM with an associated markdown README file containing XSS-able HTML tags. Upon Snyk Advisor importing the package, the XSS would run each time an end user browsed to the package's page on Snyk Advisor.

Exploits (1)

nomisec WORKING POC 2 stars
by weizman · poc
https://github.com/weizman/CVE-2023-1767

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0181
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
snyk/advisor < 2023-03-28
Published Apr 20, 2023
Tracked Since Feb 18, 2026