WhisperX tag archive

#css-injection

This page collects WhisperX intelligence signals tagged #css-injection. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-06 14:27:18 · GitHub Issues

1. Security Alert: CSS Injection Vulnerability in Capture-Eye Modal Component via Unvalidated Color Property

A critical security flaw in the Capture-Eye modal component allows for arbitrary CSS injection through the `color` attribute. The vulnerability stems from the `color` value being passed directly to `this.style.setProperty('--primary-color', this._color)` without any input validation. This injection occurs at line 637 i...

The Lab · 2026-04-13 02:22:31 · GitHub Issues

2. DynamicStyle System Exposes Medium-Severity CSS Injection Vulnerability in StyleRegistry

A security review of the DynamicStyle system has uncovered a medium-severity injection vulnerability (P1) that could allow attackers to execute arbitrary CSS code. The flaw resides in the `StyleRegistry`, which uses `dangerouslySetInnerHTML` to inject user-provided CSS property values directly into `<style>` elements w...

The Lab · 2026-05-12 07:48:26 · GitHub Issues

3. Mermaid 11.15.0 Patches CSS Injection via themeCSS and fontFamily — CVE-2026-41159

A critical CSS injection vulnerability has been identified in Mermaid, the widely-used open-source diagram and charting library. Tracked as CVE-2026-41159 (GHSA-87f9-hvmw-gh4p), the flaw stems from improper sanitization of user-supplied configuration options, allowing injected styles to apply beyond the boundaries of r...