Intel

AIKIDO-2025-10464

@polkadot/apps-config is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 15, 2025

10

Low Risk

This Affects:

JS@polkadot/apps-config
0.42.1 - 0.159.0
Fixed in 0.159.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to clickjacking and UI redress attacks due to missing security headers (X-Frame-Options and Content-Security-Policy) in the app configuration, which fail to disallow frame embedding. An attacker could exploit this by embedding the application within a malicious webpage using an iframe, tricking users into interacting with hidden or disguised elements, potentially leading to unauthorized actions or data theft.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@polkadot/apps-config is vulnerable to Cross-site Scripting (XSS) in versions 0.42.1 - 0.159.0.

How to fix this

Upgrade the @polkadot/apps-config library to a patch version.