CVE-2022-23647
published 2022-02-18CVE-2022-23647: Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.48%
71.0th percentile
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-prismjs | < node-prismjs 1.27.0+dfsg+~1.26.0-1 (bookworm) | node-prismjs 1.27.0+dfsg+~1.26.0-1 (bookworm) |
| prismjs | prism | — | — |
| prismjs | prism | >= 1.14.0 < 1.27.0 | 1.27.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
prismjs: improperly escaped output allows a XSS
vendor_redhat·2022-02-18·CVSS 7.5
CVE-2022-23647 [HIGH] CWE-79 prismjs: improperly escaped output allows a XSS
prismjs: improperly escaped output allows a XSS
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.
A Cross-site scripting attack was found in Prism. The command-line plugin did not properly es
Debian
CVE-2022-23647: node-prismjs - Prism is a syntax highlighting library. Starting with version 1.14.0 and prior t...
vendor_debian·2022·CVSS 7.5
CVE-2022-23647 [HIGH] CVE-2022-23647: node-prismjs - Prism is a syntax highlighting library. Starting with version 1.14.0 and prior t...
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.
Scope: local
bookworm: resolved (fixed in 1.27.0+dfsg+~1.26.0-1)
bullseye: resolved (fixed in 1.23.0+dfsg-1+deb11u2)
forky: resolved (fixed in
OSV
Cross-site Scripting in Prism
osv·2022-02-22
CVE-2022-23647 [HIGH] Cross-site Scripting in Prism
Cross-site Scripting in Prism
### Impact
Prism's [Command line plugin](https://prismjs.com/plugins/command-line/) can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.
Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.
### Patches
This bug has been fixed in v1.27.0.
### Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.
### References
- https://github.com/PrismJS/prism/pull/3341
GHSA
Cross-site Scripting in Prism
ghsa·2022-02-22
CVE-2022-23647 [HIGH] CWE-79 Cross-site Scripting in Prism
Cross-site Scripting in Prism
### Impact
Prism's [Command line plugin](https://prismjs.com/plugins/command-line/) can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.
Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.
### Patches
This bug has been fixed in v1.27.0.
### Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.
### References
- https://github.com/PrismJS/prism/pull/3341
OSV
CVE-2022-23647: Prism is a syntax highlighting library
osv·2022-02-18·CVSS 6.1
CVE-2022-23647 [MEDIUM] CVE-2022-23647: Prism is a syntax highlighting library
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/PrismJS/prism/commit/e002e78c343154e1c0ddf9d6a0bb85689e1a5c7chttps://github.com/PrismJS/prism/pull/3341https://github.com/PrismJS/prism/security/advisories/GHSA-3949-f494-cm99https://github.com/PrismJS/prism/commit/e002e78c343154e1c0ddf9d6a0bb85689e1a5c7chttps://github.com/PrismJS/prism/pull/3341https://github.com/PrismJS/prism/security/advisories/GHSA-3949-f494-cm99
2022-02-18
Published