Cross-site scripting in jsondiffpatch - CVE-2025-9910
Published: November 21, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.
Affected software
Astronomer with IBM
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management
How to mitigate CVE-2025-9910
Astronomer with IBM - update to 1.1.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
External References
- https://benjamine.github.io/jsondiffpatch/index.html
- https://github.com/benjamine/jsondiffpatch/commit/0e374b5dd8d7879b329a9fc18affbd46ad50dd14
- https://github.com/benjamine/jsondiffpatch/issues/383
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-12549277
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-12549276
- https://security.snyk.io/vuln/SNYK-JS-JSONDIFFPATCH-10369031