Cross-Site Scripting in nextcloud-vue-collectionsGHSA-whv6-rj84-2vh2
Fix: juliushaertl/nextcloud-vue-collections@8ec1fcaGHSA-whv6-rj84-2vh2 is a remote code execution vulnerability in nextcloud-vue-collections. A fix is available for nextcloud-vue-collections — see the affected versions and patch details below.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.
nextcloud-vue-collectionsnpmDescription
Versions of nextcloud-vue-collections prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The v-tooltip component has an insecure defaultHTML configuration that allows arbitrary JavaScript to be injected in the tooltip of a collection item. This allows attackers to execute arbitrary code in a victim's browser.
Recommendation
Upgrade to version 0.4.2 or later.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | nextcloud-vue-collections | all versions | 0.4.2npm install nextcloud-vue-collections@0.4.2 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for nextcloud-vue-collections, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update nextcloud-vue-collections to 0.4.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-whv6-rj84-2vh2 is resolved across your whole dependency graph.
Workarounds
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Frequently Asked Questions
Is GHSA-whv6-rj84-2vh2 in your dependencies?
Find it across npm, including transitive dependencies.