Loading HuntDB...

GHSA-r83x-wj75-v89r

GitHub Security Advisory

Nuclide Improper Input Validation

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.

Affected Packages

npm nuclide
Affected versions: 0 (fixed in 0.290.0)

Related CVEs

Key Information

GHSA ID
GHSA-r83x-wj75-v89r
Published
May 13, 2022 1:32 AM
Last Modified
July 21, 2023 11:24 PM
CVSS Score
9.0 /10
Primary Ecosystem
npm
Primary Package
nuclide
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.