CVE-2023-41049

@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:decentraland:single_sign_on_client:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 06:20

Type Values Removed Values Added
Summary
  • (es) @dcl/single-sign-on-client es una biblioteca npm de código abierto que gestiona los flujos de autenticación de inicio de sesión único. Una validación de entrada incorrecta en la función 'init' permite la ejecución de javascript arbitrario utilizando el prefijo 'javascript:'. Esta vulnerabilidad ha sido parcheada en la versión '0.1.0'. Se aconseja a los usuarios que actualicen. Los usuarios que no puedan actualizar deberían limitar la entrada de usuario no confiable a la función 'init'.

21 Nov 2024, 08:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 7.5
References () https://github.com/decentraland/single-sign-on-client/commit/bd20ea9533d0cda30809d929db85b1b76cef855a - Patch () https://github.com/decentraland/single-sign-on-client/commit/bd20ea9533d0cda30809d929db85b1b76cef855a - Patch
References () https://github.com/decentraland/single-sign-on-client/security/advisories/GHSA-vp4f-wxgw-7x8x - Vendor Advisory () https://github.com/decentraland/single-sign-on-client/security/advisories/GHSA-vp4f-wxgw-7x8x - Vendor Advisory

06 Sep 2023, 00:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:decentraland:single_sign_on_client:*:*:*:*:*:node.js:*:*
First Time Decentraland
Decentraland single Sign On Client
References (MISC) https://github.com/decentraland/single-sign-on-client/commit/bd20ea9533d0cda30809d929db85b1b76cef855a - (MISC) https://github.com/decentraland/single-sign-on-client/commit/bd20ea9533d0cda30809d929db85b1b76cef855a - Patch
References (MISC) https://github.com/decentraland/single-sign-on-client/security/advisories/GHSA-vp4f-wxgw-7x8x - (MISC) https://github.com/decentraland/single-sign-on-client/security/advisories/GHSA-vp4f-wxgw-7x8x - Vendor Advisory

01 Sep 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-01 20:15

Updated : 2026-06-17 06:20


NVD link : CVE-2023-41049

Mitre link : CVE-2023-41049

CVE.ORG link : CVE-2023-41049


JSON object : View

Products Affected

decentraland

  • single_sign_on_client
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')