jekyll-seo-tag is vulnerable to Cross-Site Scripting (XSS)
44
Medium Risk
The jekyll-seo-tag Liquid template puts several metadata fields - author name, author Twitter handle, canonical URL, page locale, image alt, height and width, and the Twitter card type - into HTML attributes without escaping, and serializes the JSON-LD block with jsonify without escaping </script> or <!-- sequences. Metadata containing </script><script>...</script>, for example an author name synced from _data/authors.yml or edited through a CMS, breaks out of the meta tag or the JSON-LD script block and runs as script on every page that includes the SEO tag, leading to cross-site scripting. The fix applies escape_once to the remaining attribute outputs and adds a filter that escapes the characters that can close the script block in the JSON-LD payload.
You are affected if you are using a version that falls within the vulnerable range and your site metadata, such as author name, image alt text, or canonical URL, comes from untrusted or CMS edited data.
jekyll-seo-tag is vulnerable to Cross-Site Scripting (XSS) in versions 2.2.1 - 2.9.0.
Upgrade the jekyll-seo-tag library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.