We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-48883

Chrome PHP is missing encoding in `CssSelector`



Description

Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade.

Reserved 2025-05-27 | Published 2025-05-30 | Updated 2025-05-30 | Assigner GitHub_M


MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.14.0
affected

References

github.com/...chrome/security/advisories/GHSA-3432-fmrf-7vmh

github.com/chrome-php/chrome/pull/691

github.com/...ommit/34b2b8d1691f4e3940b1e1e95d388fffe81169c8

cve.org (CVE-2025-48883)

nvd.nist.gov (CVE-2025-48883)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-48883

Support options

Helpdesk Chat, Email, Knowledgebase