allure-commandline is vulnerable to Cross-Site Scripting (XSS)
46
Medium Risk
The local report preview server decides whether a response is an HTML attachment by string-matching the raw request URI path, but resolves the file it serves from a normalized path. Because the two values disagree, spelling the same attachment URL with a doubled slash or a percent-encoded slash serves the attachment without its sandbox content security policy. Script inside an HTML attachment then executes at the preview origin instead of a sandboxed document and can read and act on the surrounding report. The fix decides the attachment flag from the normalized resolved path so equivalent spellings collapse to the same answer.
You are affected if you are using a version that falls within the vulnerable range.
allure-commandline is vulnerable to Cross-Site Scripting (XSS) in versions 2.44.0 - 2.44.1.
Upgrade the allure-commandline and/or the io.qameta.allure:allure-commandline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant