CVE-2025-58765 - wabac.js has XSS vulnerability in 404 error handling logic
CVE ID : CVE-2025-58765
Published : Sept. 9, 2025, 9:15 p.m. | 1 hour, 27 minutes ago
Description : wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter `requestURL` (derived from the original request target) is directly embedded into an inline `
Published : Sept. 9, 2025, 9:15 p.m. | 1 hour, 27 minutes ago
Description : wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter `requestURL` (derived from the original request target) is directly embedded into an inline `