Intel

AIKIDO-2026-507054

jekyll-seo-tag is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-572m-7cg5-6j5r Published 2 days ago

44

Medium Risk

This Affects:

RUBYjekyll-seo-tag
2.2.1 - 2.9.0
Fixed in 2.9.1
Are you affected? Scan for Free

TL;DR

The jekyll-seo-tag Liquid template puts several metadata fields - author name, author Twitter handle, canonical URL, page locale, image alt, height and width, and the Twitter card type - into HTML attributes without escaping, and serializes the JSON-LD block with jsonify without escaping </script> or <!-- sequences. Metadata containing </script><script>...</script>, for example an author name synced from _data/authors.yml or edited through a CMS, breaks out of the meta tag or the JSON-LD script block and runs as script on every page that includes the SEO tag, leading to cross-site scripting. The fix applies escape_once to the remaining attribute outputs and adds a filter that escapes the characters that can close the script block in the JSON-LD payload.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your site metadata, such as author name, image alt text, or canonical URL, comes from untrusted or CMS edited data.

Background info

jekyll-seo-tag is vulnerable to Cross-Site Scripting (XSS) in versions 2.2.1 - 2.9.0.

How to fix this

Upgrade the jekyll-seo-tag library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform