Junglewise Threat Intelligence

CVE-2025-58765: Webrecorder wabac.js reflected XSS in 404 error handling

CVE-2025-58765 · Severity: low · CVSS 3.1 · Published 2025-09-10

Vendors: npm.

Executive brief

wabac.js is a JavaScript web archival library used to replay captured web content. A reflected cross-site scripting (XSS) vulnerability in its 404 error page allows attackers to craft malicious URLs that execute arbitrary JavaScript in a victim's browser when accessed, potentially compromising user sessions, stealing data, or performing unauthorized actions within the affected domain.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in wabac.js v2.23.10 and below, classified as CWE-79. The vulnerability is located in the 404 error handling logic, where the requestURL parameter (derived from the original request target) is directly embedded into an inline <script> block without sanitization or escaping. An attacker can craft a malicious URL containing JavaScript payload that will execute in the victim's browser when the 404 error page is rendered. The attack requires user interaction (clicking a malicious link) and is network-accessible with no privilege requirements. CORS policies may limit the scope of exploitation depending on how wabac.js is deployed. The vulnerability is fixed in v2.23.11 and corresponding patches in downstream packages (archivewebpage v0.15.4, replaywebpage v2.3.17).

Affected products

  • Webrecorder wabac.js < 2.23.11
  • Webrecorder archivewebpage < 0.15.4
  • Webrecorder replaywebpage < 2.3.17

Timeline

  • 2025-09-10: disclosed: Published on GitHub advisory database
  • 2025-09-10: patched: wabac.js v2.23.11 released with fix

References