CVE-2025-9910

MEDIUM

jsondiffpatch < 0.7.2 - Cross-Site Scripting via HtmlFormatter::nodeBegin

Title source: llm
STIX 2.1

Description

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.

Scores

CVSS v3 4.7
EPSS 0.0004
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
n/a/jsondiffpatch < 0.7.2
n/a/org.webjars.bower:jsondiffpatch
n/a/org.webjars.npm:jsondiffpatch
npm/jsondiffpatch 0 - 0.7.2npm
Published Sep 11, 2025
Tracked Since Feb 18, 2026