gchq/CyberChef
Releases504
Frequency6 days 16 hours
Last Release
Stars35.4K
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| — | 5 MEDIUM | — | ||
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject malicious JavaScript into HTML output. This issue is fixed in version 11.2.0. | ||||
| < 11.0.0 | 7.2 HIGH | — | ||
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. | ||||
| < 8.31.2, < 8.31.3 | — | 4.3 MEDIUM | ||
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. | ||||