« Volver al listado

CVE-2019-25225

Estado: AnalizadaMedia (6.1)—

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-25225",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2019-25225",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-08T15:17:07.822892Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.0.0-beta",
              "versionType": "npm"
            }
          ],
          "packageName": "sanitize-html",
          "collectionURL": "https://registry.npmjs.org",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-09-08T10:15:33.440",
  "references": [
    {
      "url": "https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2019/CVE-2019-25225",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647"
    },
    {
      "url": "https://github.com/apostrophecms/sanitize-html/commit/712cb6895825c8bb6ede71a16b42bade42abcaf3",
      "tags": [
        "Patch"
      ],
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647"
    },
    {
      "url": "https://github.com/apostrophecms/sanitize-html/issues/293",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647"
    },
    {
      "url": "https://github.com/apostrophecms/sanitize-html/pull/156",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "596c5446-0ce5-4ba2-aa66-48b3b757a647",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code."
    }
  ],
  "lastModified": "2026-06-17T02:31:47.607",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "925E3440-F8B9-425C-86C2-3E3A2C1B7B27",
              "versionEndExcluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "596c5446-0ce5-4ba2-aa66-48b3b757a647"
}