Reflected cross-site scripting in gi-docgen - CVE-2025-11687
Published: October 14, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Fedora
Anolis OS
gi-docgen
gi-docgen-doc
How to mitigate CVE-2025-11687
gi-docgen - update to 2023.1-4
gi-docgen-doc - update to 2023.1-4
gi-docgen - addressed in versions 2025.5-1.el9, 2025.5-1.el10_0, 2025.5-1.el10_1, 2025.5-1.el10_2, 2025.5-1.fc41, 2025.5-1.fc42, 2025.5-1.fc43
External References
Related Security Bulletins
- Reflected cross-site scripting in Python gi-docgen
- Fedora 43 update for gi-docgen
- Fedora 42 update for gi-docgen
- Fedora 41 update for gi-docgen
- Fedora EPEL 10.2 update for gi-docgen
- Fedora EPEL 10.1 update for gi-docgen
- Fedora EPEL 10.0 update for gi-docgen
- Fedora EPEL 9 update for gi-docgen
- Anolis OS update for gi-docgen