Junglewise Threat Intelligence

CVE-2025-47828: Lumi H5P-Nodejs-library cross-site scripting in plain text sanitization

CVE-2025-47828 · Severity: low · CVSS 3.1 · Published 2025-05-11

Vendors: npm.

Executive brief

Lumi H5P-Nodejs-library is a Node.js library used to serve and manage H5P interactive educational content. The library failed to properly sanitize plain text strings, allowing an authenticated attacker to inject malicious scripts that could be executed in the browsers of other users viewing the content, potentially leading to session hijacking or data theft.

Technical details

A cross-site scripting (XSS) vulnerability exists in Lumi H5P-Nodejs-library (CWE-79) due to the omission of a sanitizeHtml call when processing plain text strings. The vulnerable component fails to strip or escape HTML/JavaScript in text fields that should contain only plain text. An authenticated user can inject malicious scripts through plain text input fields; these scripts execute in the context of other users' browsers when they view the affected content. The vulnerability requires authentication but spreads via stored XSS. The issue was patched in version 9.3.3 (released January 23, 2025) by adding proper HTML sanitization to text string processing.

Affected products

  • Lumi H5P-Nodejs-library before 9.3.3

Timeline

  • 2025-05-11: disclosed: Vulnerability disclosed on GitHub advisory database
  • 2025-01-23: patched: Fix merged in version 9.3.3

References