GHSA-w765-jm6w-4hhj · Severity: high · Ecosystem: npm — Webrecorder packages are vulnerable to XSS through 404 error handling logic
wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter `requestURL` (derived from the original request target) is directly embedded into an inline `<script>` block without sanitization or escaping. This allows an attacker to craft a malicious URL that executes arbitrary JavaScript in the victim’s browser. The scope may be limited by CORS policies, depending on the situation in which wabac.js is used. The vulnerability is fixed in wabac.js v2.23.11.
Conclusion & alert: CVE-2025-58765 is rated Low Risk (34.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-17 | 0.03% | 0.05% | +0.03% |
| 2 | 2026-02-05 | 0.06% | 0.03% | -0.04% |
| 3 | 2026-01-09 | — | 0.06% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
2.8 | 3.7 | [email protected] |
GHSA-w765-jm6w-4hhj · Severity: high · Ecosystem: npm — Webrecorder packages are vulnerable to XSS through 404 error handling logic
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||