CVE-2025-43954: XSS
Published Apr 20, 2025
·Updated
QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.
Affected Software
3 affected componentsFixes available
npm/@quasar/quasar-ui-qmarkdown<2.0.5
2.0.5
Quasar QMarkdown<2.0.5
Quasar QMarkdown<2.0.5
Remediation
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Apr 17, 57340
Event
via FIRST·01:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-43954?
CVE-2025-43954 has been classified as a moderate severity vulnerability due to its potential for causing XSS attacks.
2
How do I fix CVE-2025-43954?
To fix CVE-2025-43954, update QMarkdown to version 2.0.5 or later.
3
What types of attacks can CVE-2025-43954 lead to?
CVE-2025-43954 can lead to cross-site scripting (XSS) attacks through manipulation of headers.
4
Which versions of QMarkdown are affected by CVE-2025-43954?
CVE-2025-43954 affects all versions of QMarkdown prior to 2.0.5.
5
Is the no-html setting effective in preventing CVE-2025-43954?
No, the no-html setting does not prevent the vulnerability exploited by CVE-2025-43954.