{ "id": "CVE-2023-30792", "sourceIdentifier": "cve-assign@fb.com", "published": "2023-04-29T03:15:08.347", "lastModified": "2023-05-01T10:39:42.517", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources." } ], "metrics": {}, "weaknesses": [ { "source": "cve-assign@fb.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "references": [ { "url": "https://github.com/facebook/lexical/releases/tag/v0.10.0", "source": "cve-assign@fb.com" } ] }