{"id":"CVE-2020-7741","aliases":["GHSA-7jh9-6cpf-h4m7","SNYK-JS-HELLOJS-1014546"],"url":"https://o3.security/vulnerability/CVE-2020-7741","summary":"XSS in hello.js","details":"This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).","published":"2020-10-06T15:15:15.757Z","modified":"2026-07-09T12:32:59.243769Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H"},"epss":{"score":0.01476,"percentile":0.71442,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"hellojs","fixedVersion":"1.18.6"}],"fix":{"url":"https://github.com/MrSwitch/hello.js/commit/d6f5137f30de6e0ef7048191ee6ae575fdc2f669","label":"MrSwitch/hello.js@d6f5137"},"references":[{"type":"WEB","url":"https://github.com/MrSwitch/hello.js/blob/3b79ec93781b3d7b9c0b56f598e060301d1f3e73/dist/hello.all.js%23L1545"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-HELLOJS-1014546"},{"type":"FIX","url":"https://github.com/MrSwitch/hello.js/commit/d6f5137f30de6e0ef7048191ee6ae575fdc2f669"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7741"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:32:59.243769Z"}}