GHSA-v2r9-c84j-v7xm
GitHub Security Advisory
RDoc contains XSS vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Affected Packages
RubyGems
rdoc
Affected versions:
2.3.0
(fixed in 3.12.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 30, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.