原始 OSV JSON
{
"id": "GHSA-hwmc-r6mf-jh83",
"aliases": [],
"details": "Schema.org has a cross-site scripting (XSS) vulnerability via script break-out in toScript() output.",
"summary": "Schema.org has cross-site scripting (XSS) via script break-out in toScript() output",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.23.1"
},
{
"fixed": "3.23.2"
}
]
}
],
"package": {
"name": "spatie/schema-org",
"ecosystem": "Packagist"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.2"
}
]
}
],
"package": {
"name": "spatie/schema-org",
"ecosystem": "Packagist"
}
}
],
"modified": "2026-07-01T18:33:02Z",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U"
}
],
"published": "2026-07-01T18:32:31Z",
"references": [
{
"url": "https://github.com/spatie/schema-org/pull/242",
"type": "WEB"
},
{
"url": "https://github.com/spatie/schema-org/commit/be389b4759214c11cc1364a16e34a929c5af5a88",
"type": "WEB"
},
{
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/spatie/schema-org/2026-04-20.yaml",
"type": "WEB"
},
{
"url": "https://github.com/spatie/schema-org",
"type": "PACKAGE"
},
{
"url": "https://github.com/spatie/schema-org/releases/tag/4.0.2",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2026-07-01T18:32:31Z"
}
}