Intel

AIKIDO-2025-10769

sitemap is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 6, 2025

75

High Risk

This Affects:

JSsitemap
7.1.0 - 8.0.2
Fixed in 9.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Protocol Injection Vulnerability due to insufficient URL validation, which fails to prevent the injection of malicious protocols such as javascript:, data:, file:, and ftp:. This flaw allows attackers to craft URLs that bypass security measures, potentially leading to arbitrary code execution in the user's browser or unauthorized access to local files when the application processes untrusted input. Exploitation occurs when an attacker submits a manipulated URL that leverages these protocols, exploiting the lack of enforced HTTP/HTTPS restrictions and improper URL format validation to compromise system integrity or steal sensitive data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sitemap is vulnerable to Improper Input Validation in versions 7.1.0 - 8.0.2.

How to fix this

Upgrade the sitemap library to the patch version.