Executive brief
Cadwyn is a Python framework for building versioned APIs with integrated API documentation. A reflected cross-site scripting (XSS) vulnerability in the /docs endpoint allows unauthenticated attackers to inject malicious JavaScript that executes in a user's browser session. An attacker can trick a user into clicking a crafted link to steal session data, modify documentation pages, or perform unauthorized actions on behalf of the user.
Technical details
The vulnerability is a reflected XSS (CWE-79) in the /docs endpoint's version query parameter. The vulnerable code in the swagger_dashboard and redoc_dashboard functions passes unsanitized user input from the version query parameter directly to FastAPI's get_swagger_ui_html function, which embeds it into a JavaScript string without encoding. An attacker can inject a single quote followed by JavaScript code (e.g., '+ alert(document.domain) +') to escape the string context and execute arbitrary code. The attack requires only network access and user interaction (clicking a malicious link), with no authentication required. The vulnerability affects all versions prior to 5.4.3, which was released as a patch.
Affected products
- Cadwyn Cadwyn before 5.4.3
Timeline
- 2025-07-21: disclosed
- 2025-07-21: patched: Fixed in version 5.4.3