Executive brief
A security vulnerability exists in the th30d4y IP Reputation Checker, a tool used to verify the reputation of IP addresses. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized code in the user's web browser. This could result in the theft of login sessions, sensitive user data, or the display of fraudulent content.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the th30d4y/IP (npm package @w4nn4d13/ip) IP Reputation Checker application. The root cause is the direct rendering of unsanitized user input into the browser's Document Object Model (DOM) without proper neutralization of script-related HTML tags. An attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's session. This is classified under CWE-79 and CWE-80. The issue is resolved in version 2.0.1 by implementing safer DOM handling methods such as textContent.
Affected products
- th30d4y @w4nn4d13/ip 1.0.1 to before 2.0.1
Timeline
- 2026-04-17: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: CVE published to NVD
- 2026-05-08: patched: Fix released in version 2.0.1