CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-HVQH-JW65-WCPQ

GHSA-HVQH-JW65-WCPQ: Cross-Site Scripting (XSS) in devbridge-autocomplete

Alon Barad
Alon Barad
Software Engineer

Jun 22, 2026·6 min read·16 visits

Executive Summary (TL;DR)

Unescaped HTML in autocomplete suggestion categories or values can bypass client-side rendering filters and execute arbitrary JavaScript.

The devbridge-autocomplete package (jQuery-Autocomplete) fails to escape category headers and suggestion values when using default formatters formatGroup and formatResult. If suggestions contain untrusted input, arbitrary HTML and JavaScript execute directly in the victim's browser session.

Vulnerability Overview

The devbridge-autocomplete library (also known as jQuery-Autocomplete) is a client-side component designed to facilitate interactive search input suggestions. It handles queries by reading from local datasets or remote endpoints and dynamically generating search suggestion markup. This architecture introduces a typical DOM-based injection surface when suggestions are obtained from untrusted databases or external APIs.

This security vulnerability, designated as GHSA-HVQH-JW65-WCPQ, is classified as a client-side Cross-Site Scripting (XSS) flaw corresponding to CWE-79. The vulnerability is present in the component's default presentation logic, which compiles suggestion objects into HTML markup without proper neutralization.

The attack surface is prominent in applications where the search suggestion data is sourced from user-generated content. For instance, if an application implements autocomplete suggestions based on username directories, product listings, or tags, an attacker can poison these data sources with malicious payloads that execute inside the browser sessions of users interacting with the autocomplete element.

Root Cause Analysis

The root cause of GHSA-HVQH-JW65-WCPQ resides in two default formatting functions: formatGroup and formatResult. Both functions are designed to map suggestion object parameters to string representations of HTML, which are then injected directly into the DOM via jQuery's .html() method (an innerHTML-based wrapper).

In the default implementation of formatGroup, category headers are concatenated directly into a template string without any sterilization. If a group name contains HTML characters, they are preserved intact. When the library renders the autocomplete container, these tags are processed and rendered as executable nodes by the browser's HTML parser.

In the formatResult function, which handles individual autocomplete entries, the vulnerability occurs under specific logical branches. Under normal operations, the function uses regex replacements to wrap matching queries with <strong> tags. However, if the query string (currentValue) is empty—such as when minChars: 0 is specified—the function invokes an early-return branch that returns suggestion.value directly in its raw state. This leaves the suggestion value completely unescaped during initial rendering.

Code Analysis

A detailed inspection of the source files prior to version 2.0.1 reveals the precise code paths responsible for the raw injection. The vulnerable functions in src/format.ts are implemented as follows:

// Vulnerable Code Path
export function formatResult(suggestion: Suggestion, currentValue: string): string {
    if (!currentValue) {
        // Unsanitized return of the suggestion's raw value
        return suggestion.value;
    }
    // Highlight replacements continue here...
}
 
export function formatGroup(_suggestion: Suggestion, category: string): string {
    // Vulnerable string concatenation without validation
    return '<div class="autocomplete-group">' + category + "</div>";
}

In the patched version (2.0.1), the library utilizes browser-native DOM APIs rather than vulnerable string manipulation to construct the elements. The safe implementation is shown below:

// Patched Code Path (v2.0.1)
export function formatResult(suggestion: Suggestion, currentValue: string): string {
    if (!currentValue) {
        // Native DOM element creation ensures safe text assignment
        const span = document.createElement("span");
        span.textContent = suggestion.value; // Escapes special entities
        return span.innerHTML;
    }
 
    const pattern = "(" + utils.escapeRegExChars(currentValue) + ")";
    return suggestion.value
        .replace(new RegExp(pattern, "gi"), "<strong>$1</strong>")
        .replace(/&/g, "&amp;")
        .replace(/</g, "&lt;")
        .replace(/>/g, "&gt;")
        .replace(/"/g, "&quot;")
        .replace(/&lt;(\/?strong)&gt;/g, "<$1>");
}
 
export function formatGroup(_suggestion: Suggestion, category: string): string {
    // Uses native serialization for category titles
    const div = document.createElement("div");
    div.className = "autocomplete-group";
    div.textContent = category; // Escapes special entities
    return div.outerHTML;
}

While this fix successfully secures the immediate injection pathways, a variant threat remains. The regex replacement chain in the standard formatResult pathway does not escape single quotes ('). If down-stream components or custom integrations process the output of formatResult and inject it into single-quoted HTML attributes, attribute breakout and subsequent script execution remain possible.

Exploitation Methodology

Exploitation of GHSA-HVQH-JW65-WCPQ relies on introducing a payload into the dataset queried by the autocomplete handler. Because the frontend relies entirely on backend payloads being formatted by either formatGroup or formatResult, an attacker with write access to suggestion registries can inject malicious markup without direct client interaction.

To exploit the formatGroup vulnerability, the attacker registers a record containing a broken image tag with an active event handler inside the category field:

<img src=x onerror="alert('XSS-formatGroup')">

When a victim accesses the web application, clicks the autocomplete text area, and types any character that matches this group, the library constructs the list. The category string is injected via jQuery's .html(), which parses the image element and fires the onerror JavaScript payload immediately.

To exploit the formatResult vulnerability under configurations with minChars: 0, the attacker poisons a standard suggestion entry with an inline SVG element. Because minChars is set to zero, clicking or focusing on the search container initiates an empty query. The library returns the poisoned value, skips the regex-based escaping path, and renders the payload directly into the DOM.

Impact Assessment

The security impact of successful exploitation matches standard Document Object Model (DOM) Cross-Site Scripting capabilities. An attacker can execute arbitrary JavaScript within the context of the victim's current session. This allows for session token harvesting, credential harvesting, and DOM manipulation.

Because the script runs with the authorization state of the victim, an administrative user triggering the XSS payload can be forced to perform administrative changes, modify application permissions, or execute state-changing APIs without their knowledge. This elevates the risk profile in administrative control panels that utilize autocomplete fields for management purposes.

The calculated CVSS v3.1 score is 6.1 (Medium), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The requirement for user interaction (typing or selecting the autocomplete textbox) prevents a higher severity classification, but the shift in security scope (from browser sandbox boundaries to application control context) qualifies it as a high-priority vulnerability.

Remediation and Mitigation

The primary remediation path is upgrading the NPM package dependency to version 2.0.1 or higher. This release implements native DOM element generation for text sterilization, which ensures that input data cannot break out of structural text containers.

If legacy deployment requirements prevent an immediate dependency upgrade, developers can override the default formatters manually during the autocomplete initialization phase. Overriding these parameters with safe, custom sanitization routines effectively neutralizes the vulnerability:

$('#autocomplete-field').autocomplete({
    serviceUrl: '/api/suggestions',
    formatResult: function (suggestion, currentValue) {
        if (!currentValue) {
            var span = document.createElement('span');
            span.textContent = suggestion.value;
            return span.innerHTML;
        }
        // Apply standard escaping highlighting manually
        var escaped = suggestion.value
            .replace(/&/g, '&amp;')
            .replace(/</g, '&lt;')
            .replace(/>/g, '&gt;')
            .replace(/"/g, '&quot;')
            .replace(/'/g, '&#x27;');
        var pattern = '(' + escapeRegExChars(currentValue) + ')';
        return escaped.replace(new RegExp(pattern, 'gi'), '<strong>$1</strong>');
    },
    formatGroup: function (suggestion, category) {
        var div = document.createElement('div');
        div.className = 'autocomplete-group';
        div.textContent = category;
        return div.outerHTML;
    }
});

Additionally, implementing a robust Content Security Policy (CSP) that restricts script execution sources can mitigate the impact of any potential bypasses. Specifically, disabling unsafe-inline scripts and restricting external resource connections limits the capability of injected scripts to exfiltrate session parameters or load remote staging payloads.

Fix Analysis (1)

Technical Appendix

CVSS Score
6.1/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Systems

devbridge-autocomplete (NPM package)jQuery-Autocomplete (GitHub repository)

Affected Versions Detail

Product
Affected Versions
Fixed Version
devbridge-autocomplete
devbridge
< 2.0.12.0.1
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork
CVSS v3.1 Score6.1 (Medium)
Exploit StatusPoC (Proof-of-Concept)
KEV StatusNot Listed
ImpactClient-side Script Execution (Cross-Site Scripting)

MITRE ATT&CK Mapping

T1059.007Command and Scripting Interpreter: JavaScript
Execution
T1189Drive-by Compromise
Initial Access
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controlled input before it is placed in output that is used as a web page that is served to other users.

Known Exploits & Detection

GitHub Advisory DatabaseProof of concept and mitigation patterns detailed in the primary advisory context.

Vulnerability Timeline

Official patch committed to GitHub repository
2026-05-21
GHSA-HVQH-JW65-WCPQ advisory published
2026-05-21
Patched package 2.0.1 released to NPM registry
2026-05-21

References & Sources

  • [1]GHSA-HVQH-JW65-WCPQ GitHub Security Advisory
  • [2]Vulnerability Remediation Commit
  • [3]Project Repository Page
  • [4]NPM Package Metadata Endpoint

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•GHSA-596P-6JV8-775V
5.1

GHSA-596p-6jv8-775v: Authenticated Leak of Secret Environment Variables in Craft CMS

An authenticated information disclosure vulnerability in Craft CMS allows high-privilege administrators to extract sensitive environment variables, including the CRAFT_SECURITY_KEY and database credentials, using a blind error-based template injection attack within element select condition rules.

Amit Schendel
Amit Schendel
2 views•5 min read
•about 2 hours ago•CVE-2026-71554
5.3

CVE-2026-71554: HTTP Request Smuggling via Duplicate Host Headers in h2 Protocol Stack

A protocol-parsing vulnerability in the pure-Python HTTP/2 library 'h2' (versions <= 4.4.0) allows unauthenticated remote attackers to perform HTTP Request Smuggling (CWE-444). The vulnerability exists because the library does not validate the uniqueness of 'Host' headers in incoming HTTP/2 request streams. When an upstream gateway parses such requests and downgrades them to HTTP/1.1 for internal backend servers, the resulting stream contains duplicate Host headers, which leads to parsing inconsistency and potential bypass of security filters.

Alon Barad
Alon Barad
3 views•5 min read
•about 3 hours ago•GHSA-957R-QF9P-67XW
4.9

GHSA-957R-QF9P-67XW: Arbitrary File Read via SplFileObject in Craft CMS Twig Extension

An information disclosure vulnerability in Craft CMS allows users with administrative or non-sandboxed template-authoring privileges to read arbitrary system and configuration files. The issue stems from an incomplete class instantiation blocklist in the Twig template extension, which omitted PHP's built-in SplFileObject class.

Alon Barad
Alon Barad
4 views•6 min read
•about 4 hours ago•CVE-2026-14793
5.3

CVE-2026-14793: Authorization Bypass in Craft CMS GlobalsController actionReorderSets

An authorization bypass vulnerability in Craft CMS allows authenticated control panel users with low privileges to reorder global sets. This alters structure and writes to the project configuration database schema without administrative rights.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 5 hours ago•CVE-2026-71438
2.4

CVE-2026-71438: Prototype Pollution in Mermaid Configuration APIs

Prior to versions 10.9.8 and 11.16.1, Mermaid is vulnerable to prototype pollution via its deep-merge utility function assignWithDepth. This helper is invoked by public configuration-setting interfaces, specifically mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig. Because assignWithDepth recursively merges developer-provided properties into Mermaid's internal configuration state without proper sanitization, an attacker who can control or influence the configuration payload can corrupt the global Object.prototype. This vulnerability can lead to security bypasses, cross-site scripting (XSS), or execution flow modifications in applications using vulnerable Mermaid integrations.

Alon Barad
Alon Barad
5 views•7 min read
•about 6 hours ago•CVE-2026-67309
7.8

CVE-2026-67309: Path Traversal and Authentication Bypass in Traefik RewriteTarget Middleware

A high-severity path traversal vulnerability exists in Traefik's Kubernetes Ingress NGINX provider. The flaw resides in the RewriteTarget middleware, which is auto-generated when an Ingress resource specifies the `nginx.ingress.kubernetes.io/rewrite-target` annotation. This allows remote, unauthenticated attackers to bypass route-level authentication and access restricted downstream endpoints by exploiting a parser differential.

Alon Barad
Alon Barad
4 views•7 min read