{"id":"GHSA-2pwh-52h7-7j84","summary":"JavaScript execution via malicious molfiles (XSS)","details":"### Impact\nThe viewer plugin implementation of `\u003cmol:molecule\u003e` renders molfile data directly inside a `\u003cscript\u003e` tag without any escaping. Arbitrary JavaScript code can thus be executed in the client browser via crafted molfiles.\n\n### Patches\nPatched in v0.3.0: Molfile data is now rendered as value of a hidden `\u003cinput\u003e` tag and escaped via JSF's mechanisms.\n\n### Workarounds\nNo workaround available.","aliases":["CVE-2024-0758"],"modified":"2026-05-06T12:44:54.171418047Z","published":"2021-04-16T19:52:49Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-04-13T17:35:23Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/ipb-halle/MolecularFaces/security/advisories/GHSA-2pwh-52h7-7j84"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0758"},{"type":"PACKAGE","url":"https://github.com/ipb-halle/MolecularFaces"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-2pwh-52h7-7j84"}],"affected":[{"package":{"name":"de.ipb-halle:molecularfaces","ecosystem":"Maven","purl":"pkg:maven/de.ipb-halle/molecularfaces"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}],"versions":["0.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-2pwh-52h7-7j84/GHSA-2pwh-52h7-7j84.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}