{"id":"CVE-2025-9910","aliases":["GHSA-33vc-wfww-vjfv"],"url":"https://o3.security/vulnerability/CVE-2025-9910","summary":"jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin","details":"### Vulnerability in jsondiffpatch\n\nVersions of `jsondiffpatch` prior to `0.7.2` are vulnerable to Cross-site Scripting (XSS) in the `HtmlFormatter` (`HtmlFormatter::nodeBegin`). When diffs are rendered to HTML using the built-in formatter, untrusted payloads can inject scripts and execute in the context of a consuming web page.\n\n**Affected versions:** >= 0, < 0.7.2\n**Patched version:** 0.7.2\n\n**Remediation**\nUpgrade to `jsondiffpatch` `0.7.2` or later. The fix hardens the HTML formatter to avoid script injection.\n\n**Workarounds**\nAvoid using the HTML formatter on untrusted diffs, or sanitize/escape the rendered output.","published":"2025-09-11T05:00:02.071Z","modified":"2026-08-12T03:51:32.425594334Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"jsondiffpatch","fixedVersion":"0.7.2"}],"fix":{"url":"https://github.com/benjamine/jsondiffpatch/commit/0e374b5dd8d7879b329a9fc18affbd46ad50dd14","label":"benjamine/jsondiffpatch@0e374b5"},"references":[{"type":"WEB","url":"https://benjamine.github.io/jsondiffpatch/index.html"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-12549277"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-12549276"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-JSONDIFFPATCH-10369031"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9910.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9910"},{"type":"REPORT","url":"https://github.com/benjamine/jsondiffpatch/issues/383"},{"type":"FIX","url":"https://github.com/benjamine/jsondiffpatch/commit/0e374b5dd8d7879b329a9fc18affbd46ad50dd14"},{"type":"PACKAGE","url":"https://github.com/benjamine/jsondiffpatch"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.425594334Z"}}