Skip to content

DOM-Based Cross-Site Scripting (XSS) Vulnerability in IP Reputation Checker

Moderate
0x5t4l1n published GHSA-j7wv-7j97-9qh9 Apr 17, 2026

Package

npm @w4nn4d13/ip (npm)

Affected versions

1.0.1

Patched versions

2.0.1

Description

Security Summary

A DOM-Based Cross-Site Scripting (XSS) (CWE-79) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript.

Impact:
This could lead to session hijacking, credential theft, phishing attacks, and full client-side compromise.

Fix (Reference):
Use safe DOM handling methods like textContent instead of rendering raw HTML, and validate/sanitize all user inputs.

Advisory:
GHSA-j7wv-7j97-9qh9

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE ID

CVE-2026-41575

Weaknesses

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as <, >, and & that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages. Learn more on MITRE.

Doubled Character XSS Manipulations

The web application does not filter user-controlled input for executable script disguised using doubling of the involved characters. Learn more on MITRE.

Credits