GNOME gi-docgen Reflected DOM-Based Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in GNOME gi-docgen. This issue allows for arbitrary execution of JavaScript in the context of the page, which could lead to access of the Document Object Model (DOM), theft of session cookies, and other client-side attacks. The vulnerability arises because gi-docgen does not properly encode search terms before inserting them into HTML. It can be exploited by sending a crafted URL that includes a malicious value in the 'q' GET parameter.

Impact

Exploitation of this vulnerability allows for reflected DOM-based cross-site scripting, where an attacker can execute arbitrary JavaScript in the victim's browser. This could be used to steal cookies, including session cookies, and perform other client-side attacks.

Added: Jan 26, 2026, 8:30 PM
Updated: Jan 26, 2026, 8:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.2
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.