CVE-2024-0758: JavaScript execution via malicious molfiles (XSS)
(updated )
The viewer plugin implementation of <mol:molecule> renders molfile data directly inside a <script> tag without any escaping. Arbitrary JavaScript code can thus be executed in the client browser via crafted molfiles.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-0758 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →