CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure

CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure-渗透云记 - 专注于网络安全与技术分享
CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 – GitHub Personal Access Token Exposure

漏洞描述

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token, intended for build-time API access only, is inadvertently included in client-side JavaScript bundles, making it accessible to anyone who can view the website's source code.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享