CVE-2025-53624 PUBLISHED

docusaurus-plugin-content-gists Exposes GitHub Personal Access Token

Assigner: GitHub_M
Reserved: 07.07.2025 Published: 09.07.2025 Updated: 10.07.2025

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token, intended for build-time API access only, is inadvertently included in client-side JavaScript bundles, making it accessible to anyone who can view the website's source code. This vulnerability is fixed in 4.0.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor webbertakken
Product docusaurus-plugin-content-gists
Versions
  • Version < 4.0.0 is affected

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE