Loading HuntDB...

GHSA-hrgx-7j6v-xj82

GitHub Security Advisory

Reflected cross-site scripting (XSS) vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

This security advisory relates to a capability for an attacker to exploit a reflected cross-site scripting vulnerability when using the `@keystone-6/auth` package.

#### Impact
The vulnerability can impact users of the administration user interface when following an untrusted link to the `signin` or `init` page.
This is a targeted attack and may present itself in the form of phishing and or chained in conjunction with some other vulnerability.

## Vulnerability mitigation
Please upgrade to `@keystone-6/auth >= 1.0.2`, where this vulnerability has been closed.
If you are using `@keystone-next/auth`, we **strongly** recommend you upgrade to `@keystone-6`.

### Workarounds
If for some reason you cannot upgrade the dependencies in software, you could alternatively

- disable the administration user interface, or
- if using a reverse-proxy, strip query parameters when accessing the administration interface

### References
https://owasp.org/www-community/attacks/xss/

Thanks to Shivansh Khari (@Shivansh-Khari) for discovering and reporting this vulnerability

Affected Packages

npm @keystone-6/auth
Affected versions: 0 (fixed in 1.0.2)
npm @keystone-next/auth
Affected versions: 0 (last affected: 37.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-hrgx-7j6v-xj82
Published
January 12, 2022 9:55 PM
Last Modified
January 19, 2022 5:42 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
@keystone-6/auth
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.