Intel

AIKIDO-2025-10395

zotonic_stdlib is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 23, 2025

10

Low Risk

This Affects:

Elixirzotonic_stdlib
0.1.0 - 1.23.1
Fixed in 1.24.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to XSS attacks when processing HTML comments containing or > characters. Attackers can exploit this by injecting malicious scripts inside comments (e.g., !-- script>alert('XSS')/script> -->), which some editors may execute due to improper sanitization. This allows arbitrary code execution, compromising user data or session integrity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

zotonic_stdlib is vulnerable to Cross-site Scripting (XSS) in versions 0.1.0 - 1.23.1.

How to fix this

Upgrade the zotonic_stdlib library to the patch version.