Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 npm
Not in CISA KEV

Cross-Site Scripting in jquery-mobileGHSA-fj93-7wm4-8x2g

Fix: jquery/jquery-mobile#8649

GHSA-fj93-7wm4-8x2g is a security vulnerability in jquery-mobile. No vendor fix is recorded yet; mitigation options are listed below.

Published
Updated
Affected
1 pkg
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 27, 2021 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.

jquery-mobilenpm
2Kdownloads / week

Description

All version of jquery-mobile are vulnerable to Cross-Site Scripting. The package checks for content in location.hash and if a URL is found it does an XmlHttpRequest (XHR) to the URL and renders the response with innerHTML. It fails to validate the Content-Type of the response, allowing attackers to include malicious payloads as part of query parameters that are reflected back to the user. A response such as {"q":"<iframe/src='javascript:alert(1)'></iframe>","results":[]} would be parsed as HTML and the JavaScript payload executed.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Affected Packages

1 total
EcosystemPackageVulnerable rangeFix
📦npmjquery-mobileall versionsNo fix

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for jquery-mobile, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Remediation status

    No patched version of jquery-mobile has shipped for GHSA-fj93-7wm4-8x2g yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Mitigate without a patch

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

All version of `jquery-mobile` are vulnerable to Cross-Site Scripting. The package checks for content in `location.hash` and if a URL is found it does an XmlHttpRequest (XHR) to the URL and renders the response with `innerHTML`. It fails to validate the `Content-Type` of the response, allowing attackers to include malicious payloads as part of query parameters that are reflected back to the user. A response such as `{"q":"<iframe/src='javascript:alert(1)'></iframe>","results":[]}` would be parsed as HTML and the JavaScript payload executed. ## Recommendation No fix is currently available. C
O3 Security · Impact-Aware SCA

Is GHSA-fj93-7wm4-8x2g in your dependencies?

Find it across npm, including transitive dependencies.

Cross-Site Scripting in jquery-mobile