Intel

AIKIDO-2025-10980

validator is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 26, 2025

43

Medium Risk

This Affects:

JSvalidator
5.0.0 - 13.15.25
Fixed in 13.15.26
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting due to a URL Validation Bypass using URL Encoding, where the isURL function fails to properly validate URLs containing URL-encoded characters. It allows attackers to craft URLs that evade validation checks, and by tricking users into clicking such links, they can execute arbitrary JavaScript in the victim's browser, leading to cross-site scripting (XSS) attacks and potential compromise of user data or session hijacking.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

validator is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 13.15.25.

How to fix this

Upgrade the validator library to the patch version.