Junglewise Threat Intelligence

CVE-2025-57665: Element Plus Link component insufficient href input validation

CVE-2025-57665 · Severity: medium · CVSS 4 · Published 2025-09-09

Vendors: npm.

Executive brief

Element Plus is a Vue.js 3 UI component library widely used in web applications. The Link component (el-link) fails to validate the href attribute, allowing attackers to inject dangerous protocols like javascript:, data:, or file: that can execute malicious code in users' browsers or redirect users to phishing sites. Applications using user-controlled URLs in this component without additional validation are vulnerable to XSS attacks and phishing campaigns.

Technical details

The vulnerability exists in the el-link component's handling of the href attribute. The component renders the href value directly to an HTML anchor (<a>) tag without validating the protocol or sanitizing the URL. Root cause: the link.vue template uses :href="disabled || !href ? undefined : href" without any validation of the href content. Attack vector is network-based; no authentication is required. An attacker can craft a malicious URL containing javascript:, data:, or file: protocols, which when clicked by a user will execute arbitrary JavaScript or trigger other client-side attacks. As of version 2.11.0, the Element Plus team added security documentation recommending developers implement URL sanitization (e.g., allowlist http: and https: protocols only), but the component itself does not enforce this protection. The advisory references commit 110d4e1 and pull request #21711 which add security warnings to the documentation.

Affected products

  • Element Plus element-plus prior to 2.11.0

Timeline

  • 2025-09-09: disclosed: Vulnerability disclosed via GHSA-5m5x-9j46-h678 and CVE-2025-57665
  • 2025-09-10: advisory: Security warning documentation added via PR #21711 in version 2.11.0
  • 2025-08-15: other: Documentation security warning merged into dev branch

References

Related threats