Executive brief
nice-select2 is a JavaScript library used to create customizable dropdown menus on websites. A security flaw allows attackers to inject malicious scripts into these dropdowns if the website displays untrusted data within a selection menu. If a user interacts with the affected menu, the attacker's script could run in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A Cross-site Scripting (XSS) vulnerability exists in nice-select2 versions prior to 2.4.1. The issue stems from the library's failure to properly sanitize or escape content passed into the native <select> element before rendering it into the custom DOM structure (specifically within the .current span and .list items). An attacker can provide a malicious payload, such as a script tag within an option label, which is then executed in the context of the victim's browser session when the page is viewed or interacted with. This is a DOM-based XSS vulnerability triggered by unsafe DOM manipulation. The vulnerability is resolved in version 2.4.1 by implementing proper output encoding.
Affected products
- bluzky nice-select2 < 2.4.1
Timeline
- 2025-07-30: disclosed: Vulnerability reported via GitHub issue #97
- 2026-07-27: advisory: Snyk advisory published
- 2026-07-28: advisory: NVD entry published