{"id":"CVE-2025-11687","summary":"Gi-docgen: reflected dom xss in gi-docgen","details":"A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).","aliases":["GHSA-6p6h-rqr6-62mv","PYSEC-2026-1402"],"modified":"2026-07-11T03:54:08.331701735Z","published":"2026-01-26T19:36:28.947Z","related":["SUSE-SU-2026:21159-1","openSUSE-SU-2025:15634-1","openSUSE-SU-2026:11185-1","openSUSE-SU-2026:20497-1"],"database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11687.json","cna_assigner":"redhat"},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-11687"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11687.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11687"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2403536"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gi-docgen/-/issues/228"},{"type":"PACKAGE","url":"https://gitlab.gnome.org/GNOME/gi-docgen/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/gi-docgen","events":[{"introduced":"0"},{"fixed":"9eedfa6572cc9929583f926493751adb85805ffb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2025.5"}],"source":"AFFECTED_FIELD"}}],"versions":["2025.3","2025.2","2024.1","2023.3","2023.2","2023.1","2022.2","2022.1","2021.8","2021.7","2021.6","2021.5","2021.4","2021.1","2021.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-11687.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}