[{"uuid":"GSA_kwCzR0hTQS1yeHJjLXJndjQtanB2eM4AA2j_","url":"https://github.com/advisories/GHSA-rxrc-rgv4-jpvx","title":"React Developer Tools extension Improper Authorization vulnerability","description":"The React Developer Tools extension registers a message listener with window.addEventListener('message', \u003clistener\u003e) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-10-19T15:31:08.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-5654","https://gist.github.com/CalumHutton/1fb89b64409570a43f89d1fd3274b231","https://github.com/facebook/react/pull/27417","https://github.com/facebook/react/commit/09285d5a7f1c08bec09f44cec3d0518a603597fc","https://github.com/facebook/react/commit/94d5b5b2bf5204ebd289a113989c0e2c51b626ef","https://github.com/advisories/GHSA-rxrc-rgv4-jpvx"],"source_kind":"github","identifiers":["GHSA-rxrc-rgv4-jpvx","CVE-2023-5654"],"repository_url":"https://github.com/facebook/react","blast_radius":38.03066715806921,"created_at":"2023-10-20T23:05:58.112Z","updated_at":"2026-10-09T14:15:29.666Z","epss_percentage":0.00467,"epss_percentile":0.37753,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yeHJjLXJndjQtanB2eM4AA2j_","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yeHJjLXJndjQtanB2eM4AA2j_","packages":[{"ecosystem":"npm","package_name":"react-devtools-core","versions":[{"first_patched_version":"4.28.4","vulnerable_version_range":"\u003c 4.28.4"}],"purl":"pkg:npm/react-devtools-core"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yeHJjLXJndjQtanB2eM4AA2j_/related_packages","related_advisories":[]}]