VYPR
High severity8.6OSV Advisory· Published Sep 15, 2025· Updated Apr 15, 2026

CVE-2025-59332

CVE-2025-59332

Description

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Dolfinus/3dalloyOSV2 versions
    1.0, 1.1, 1.2, …+ 1 more
    • (no CPE)range: 1.0, 1.1, 1.2, …
    • (no CPE)range: >=1.0, <=1.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.