VYPR
Unrated severityNVD Advisory· Published Jun 9, 2021· Updated Aug 4, 2024

CVE-2021-34364

CVE-2021-34364

Description

Refined GitHub extension before 21.6.8 allowed XSS via crafted links in documents, mitigated by GitHub's CSP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Refined GitHub extension before 21.6.8 allowed XSS via crafted links in documents, mitigated by GitHub's CSP.

Vulnerability

The Refined GitHub browser extension, prior to version 21.6.8, contains a stored cross-site scripting (XSS) vulnerability (CWE-79). An attacker can inject arbitrary HTML or JavaScript by crafting a malicious link within a document (e.g., an issue, pull request, or comment) on GitHub. The vulnerability resides in the extension's handling of link elements in page content. Affected versions: all versions up to and including 21.6.1; fixed in 21.6.8 [1][2].

Exploitation

An attacker needs only the ability to post a crafted link on a GitHub page that is viewed by a victim running the vulnerable extension. No authentication or special network position is required beyond standard GitHub access. The attacker creates a link with specially crafted attributes (e.g., a href containing JavaScript or event handlers) that bypasses the extension's filtering. When the victim's browser renders the page with Refined GitHub active, the extension processes the link and executes the injected script within the context of the github.com origin [2].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the GitHub session. This could lead to session hijacking, data theft (e.g., repository content, access tokens), and unauthorized actions on behalf of the victim. GitHub's strict Content-Security-Policy (CSP) partially mitigates the risk, but the XSS could still bypass certain CSP restrictions depending on the injection point [1][2].

Mitigation

The vulnerability is fixed in Refined GitHub version 21.6.8, released on 2021-06-09 [1]. Users should update the browser extension to 21.6.8 or later. No workaround other than disabling the extension is available for earlier versions. GitHub's CSP provides an additional layer of defense but is not a complete fix [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.