Executive brief
Element Plus is a Vue.js 3 UI component library widely used in web applications. The Link component (el-link) fails to validate the href attribute, allowing attackers to inject dangerous protocols like javascript:, data:, or file: that can execute malicious code in users' browsers or redirect users to phishing sites. Applications using user-controlled URLs in this component without additional validation are vulnerable to XSS attacks and phishing campaigns.
Technical details
The vulnerability exists in the el-link component's handling of the href attribute. The component renders the href value directly to an HTML anchor (<a>) tag without validating the protocol or sanitizing the URL. Root cause: the link.vue template uses :href="disabled || !href ? undefined : href" without any validation of the href content. Attack vector is network-based; no authentication is required. An attacker can craft a malicious URL containing javascript:, data:, or file: protocols, which when clicked by a user will execute arbitrary JavaScript or trigger other client-side attacks. As of version 2.11.0, the Element Plus team added security documentation recommending developers implement URL sanitization (e.g., allowlist http: and https: protocols only), but the component itself does not enforce this protection. The advisory references commit 110d4e1 and pull request #21711 which add security warnings to the documentation.
Affected products
- Element Plus element-plus prior to 2.11.0
Timeline
- 2025-09-09: disclosed: Vulnerability disclosed via GHSA-5m5x-9j46-h678 and CVE-2025-57665
- 2025-09-10: advisory: Security warning documentation added via PR #21711 in version 2.11.0
- 2025-08-15: other: Documentation security warning merged into dev branch
References
- https://github.com/element-plus/element-plus/pull/21711
- https://github.com/element-plus/element-plus/commit/110d4e1d7e150ccb829771c7319d31ce777d102f
- https://element-plus.org/en-US/component/link.html
- https://github.com/element-plus/element-plus
- https://github.com/element-plus/element-plus/blob/dev/packages/components/link/src/link.vue
- https://www.npmjs.com/package/element-plus