GHSA-fx6f-382r-j72c: XSS
On 5 June 2026 CyberChef received a security vulnerability report from @hyuunnn detailing a vulnerability in the Series Chart operation, where malicious input could result in prototype pollution of the data structures outputted from the operation. Other operations following Series Chart could have their behaviour manipulated by the attacker-controlled prototype, for example, injecting malicious content into their HTML output.
In this case, a demonstration was provided that chained the Series Chart operation with the Parse UDP operation to cause attacker controlled JavaScript to be executed.
Details When the Series Chart operation parses user-supplied CSV, it accepts proto as a key and uses it to pollute the object. The objToTbale function in src/core/lib/Protocol.mjs, used in a number of IP parsing operations, renders data items within <td> tags without escaping. These bugs can be chained to produce an XSS vulnerability.
Proof of Concept https://gchq.github.io/CyberChef/#recipe=Serieschart('CRLF','Comma','',1,'')ParseUDP('Raw')&input=X19wcm90b19fLDxpbWcgc3JjPXggb25lcnJvcj1hbGVydChkb2N1bWVudC5kb21haW4pPiwxParseUDP('Raw')&input=X19wcm90b19fLDxpbWcgc3JjPXggb25lcnJvcj1hbGVydChkb2N1bWVudC5kb21haW4pPiwx)
Encoded input data is: proto,<img src=x onerror=alert(document.domain)>,1
Impact Objects with attacker controlled prototypes could be processed by CyberChef operations. This enabled control of the output of some operations, and in particular, the ability to insert malicious JavaScript into the output of the Parse UDP operation.
Patches This has been patched in release v11.2.0.
Workarounds No workarounds are available. Users must upgrade to CyberChef v11.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/cyberchefto a version that resolves this vulnerability.Fixed in 11.2.0 - Upgrade
Upgrade
CyberChefto a version that resolves this vulnerability.Fixed in v11.2.0
Event History
Frequently Asked Questions
What interaction is required for exploitation?
An attacker needs to cause a user to process attacker-controlled CSV through the Series Chart operation and then use a downstream operation that renders the polluted data into HTML. The provided demonstration chains Series Chart with Parse UDP and results in attacker-controlled JavaScript execution.
Which input and operation behavior enable the issue?
Series Chart accepts __proto__ as a CSV key, allowing prototype pollution of objects it outputs. The objToTbale function used by several IP parsing operations then renders data in td elements without escaping it.
How can I determine whether a workflow is exposed?
Review CyberChef recipes that run Series Chart on untrusted CSV and subsequently use IP parsing operations that rely on objToTbale, including the demonstrated Parse UDP chain. Recipes that render values derived from the Series Chart output into HTML are the relevant exposure path.