CVE-2025-11687
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
Published 2026-01-26. Last modified 2026-06-17.