{"id":"GHSA-j4gv-6x9v-v23g","aliases":[],"url":"https://o3.security/vulnerability/GHSA-j4gv-6x9v-v23g","summary":"OMERO.web uses jquery-form library, which may be vulnerable to XSS attack","details":"### Impact\nOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks.\n\n### Patches\nUser should upgrade OMERO.web to 5.29.3 or higher.\n\n### Workarounds\nNone.\n\n### Resources\nhttps://github.com/jquery-form/form/issues/604","published":"2025-11-24T23:35:30Z","modified":"2025-11-24T23:44:53.696109Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"omero-web","fixedVersion":"5.29.3"}],"fix":{"url":"https://github.com/ome/omero-web/commit/a3eadf722cfada2b844b97abe65baf5856e77c4f","label":"ome/omero-web@a3eadf7"},"references":[{"type":"WEB","url":"https://github.com/ome/omero-web/security/advisories/GHSA-j4gv-6x9v-v23g"},{"type":"WEB","url":"https://github.com/jquery-form/form/issues/604"},{"type":"WEB","url":"https://github.com/ome/omero-web/commit/a3eadf722cfada2b844b97abe65baf5856e77c4f"},{"type":"PACKAGE","url":"https://github.com/ome/omero-web"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-24T23:44:53.696109Z"}}