Description
A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
Problem types
Product status
2.1
2.2
2.3
2.4
2.5.0
Timeline
| 2026-05-01: | Advisory disclosed |
| 2026-05-01: | VulDB entry created |
| 2026-05-01: | VulDB entry last update |
Credits
Yu-Bao (VulDB User)
VulDB CNA Team
References
github.com/nextlevelbuilder/ui-ux-pro-max-skill/issues/247
vuldb.com/vuln/360549 (VDB-360549 | nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting)
vuldb.com/vuln/360549/cti (VDB-360549 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/805510 (Submit #805510 | nextlevelbuilder ui-ux-pro-max-skill 2.5.0 Slide Generator Multiple Stored XSS)
github.com/nextlevelbuilder/ui-ux-pro-max-skill/issues/247
github.com/nextlevelbuilder/ui-ux-pro-max-skill/pull/274
github.com/nextlevelbuilder/ui-ux-pro-max-skill/