CVE-2025-48051 Information
May 16, 2025
cve
Description
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
Reference
https://github.com/lichess-org/lila/blob/7b82f35d15f9113ac8a0a9271d34bef4f6119e9f/ui/site/src/powertip.ts#L60 https://github.com/lichess-org/lila/commit/ab0beaf0ad671761705d9274663c5dc450608527 https://github.com/lichess-org/lila/security/advisories/GHSA-9xhx-p3c5-p4v6 https://github.com/lichess-org/lila/security/advisories/GHSA-9xhx-p3c5-p4v6
Share on: