Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: lychee

Found 1 matching suggestions

View:
Compact
Detailed
updated 1 month ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • LycheeSlicer
    • lycheeslicer
    • tests.testers.lycheeLinkCheck.ok
    • tests.testers.lycheeLinkCheck.network
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)

Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and rendered using `{!! $item->summary !!}` (Blade unescaped output) in the RSS, Atom, and JSON feed templates. The `/feed` endpoint is publicly accessible without authentication, allowing any RSS reader to execute attacker-controlled JavaScript. Version 7.5.3 fixes the issue.

Affected products

Lychee
  • ==< 7.5.3

Matching in nixpkgs

pkgs.lychee

Fast, async, stream-based link checker written in Rust

Ignored packages (4)

pkgs.lycheeslicer

All-in-one 3D slicer for resin and FDM printers

Package maintainers

Upstream advisory: https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-5574-7f3r-hm9j
Upstream patch: https://github.com/LycheeOrg/Lychee/commit/d2e2606a0223d5a384d5b806db1b31eb587adc5c