CVE-2026-41575

In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been patched in version 2.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:th30d4y:w4nn4d13\/ip:*:*:*:*:*:node.js:*:*

History

12 May 2026, 21:11

Type Values Removed Values Added
First Time Th30d4y w4nn4d13\/ip
Th30d4y
References () https://github.com/th30d4y/IP/security/advisories/GHSA-j7wv-7j97-9qh9 - () https://github.com/th30d4y/IP/security/advisories/GHSA-j7wv-7j97-9qh9 - Vendor Advisory
CPE cpe:2.3:a:th30d4y:w4nn4d13\/ip:*:*:*:*:*:node.js:*:*

08 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 15:16

Updated : 2026-05-12 21:11


NVD link : CVE-2026-41575

Mitre link : CVE-2026-41575

CVE.ORG link : CVE-2026-41575


JSON object : View

Products Affected

th30d4y

  • w4nn4d13\/ip
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)