Intel

AIKIDO-2025-10771

github.com/victoriametrics/victorialogs-datasource is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 6, 2025

41

Medium Risk

This Affects:

Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) attacks due to unsanitized href attributes. This vulnerability arises when user-controlled input is assigned directly to the href property of anchor tags without proper sanitization. An attacker can exploit this by injecting malicious JavaScript URLs (for example, javascript:alert('XSS')) into the href field. If unsuspecting users click on the manipulated link, the arbitrary script executes in their browser context, potentially leading to session hijacking or other malicious actions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/victoriametrics/victorialogs-datasource is vulnerable to Cross-Site Scripting (XSS) in versions 0.15.0 - 0.21.2.

How to fix this

Upgrade the github.com/victoriametrics/victorialogs-datasource library to the patch version.