Home

Description

A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

PUBLISHED Reserved 2025-04-22 | Published 2026-04-09 | Updated 2026-04-09 | Assigner mitre

References

github.com/rrweb-io/rrweb

github.com/...b-io/rrweb/tree/master/packages/rrweb-snapshot

github.com/rrweb-io/rrweb/issues/1817

cve.org (CVE-2025-45806)

nvd.nist.gov (CVE-2025-45806)

Download JSON