CVE-2025-48051: Lichess Powertip.ts
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
Affected products
- Lichess Powertip.ts: before 2025-03-27 (fixed in 2025-03-27)
Published 2025-05-15. Last modified 2026-06-17.