{"id":"GHSA-hwmc-r6mf-jh83","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hwmc-r6mf-jh83","summary":"Schema.org has cross-site scripting (XSS) via script break-out in toScript() output","details":"Schema.org has a cross-site scripting (XSS) vulnerability via script break-out in toScript() output.","published":"2026-07-01T18:32:31Z","modified":"2026-07-01T18:45:35.784333158Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"spatie/schema-org","fixedVersion":"3.23.2"},{"ecosystem":"Packagist","name":"spatie/schema-org","fixedVersion":"4.0.2"}],"fix":{"url":"https://github.com/spatie/schema-org/pull/242","label":"spatie/schema-org#242"},"references":[{"type":"WEB","url":"https://github.com/spatie/schema-org/pull/242"},{"type":"WEB","url":"https://github.com/spatie/schema-org/commit/be389b4759214c11cc1364a16e34a929c5af5a88"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/spatie/schema-org/2026-04-20.yaml"},{"type":"PACKAGE","url":"https://github.com/spatie/schema-org"},{"type":"WEB","url":"https://github.com/spatie/schema-org/releases/tag/4.0.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-01T18:45:35.784333158Z"}}