Medium severity6.1NVD Advisory· Published Jul 6, 2021· Updated Jun 17, 2026
CVE-2021-35440
CVE-2021-35440
Description
Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
smashingRubyGems | < 1.3.5 | 1.3.5 |
Affected products
3- cpe:2.3:a:smashing_project:smashing:1.3.4:*:*:*:*:*:*:*
- Smashing/Smashingdescription
Patches
Vulnerability mechanics
References
7- github.com/Smashing/smashing/pull/186nvdPatchThird Party AdvisoryWEB
- github.com/Smashing/smashing/pull/186nvdPatchThird Party Advisory
- github.com/Smashing/smashing/blob/ad7325f159f89854ca4e7d94e7be9bee507b6d46/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- github.com/advisories/GHSA-254j-mmc5-qhpxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-35440ghsaADVISORY
- github.com/Smashing/smashing/pull/186/commits/f4648137ae77aa2a9ccd14b2e6eeaed2cfb32da3ghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/smashing/CVE-2021-35440.ymlghsaWEB
News mentions
0No linked articles in our index yet.