CVE-2026-41575 Details
Description
In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been patched in version 2.0.1.
A DOM-Based Cross-Site Scripting (XSS) vulnerability has been identified in the th30d4y/IP IP Reputation Checker application, affecting versions 1.0.1 prior to 2.0.1. The vulnerability arises from unsanitized user input being directly rendered in the browser, which allows attackers to execute arbitrary JavaScript. This issue could lead to session hijacking, credential theft, phishing attacks, and full client-side compromise.
Users are advised to update to version 2.0.1. For those maintaining version 1.0.1, it is recommended to use safe DOM handling methods, such as 'textContent', instead of rendering raw HTML, and to validate or sanitize all user inputs.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/th30d4y/IP/security/advisories/GHSA-j7wv-7j97-9qh9 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| th30d4y w4nn4d13/ip | >= 1.0.1, < 2.0.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |