GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in CyberChef’s Base64 Offset Feature |
Wed, 29 Apr 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. | |
| First Time appeared |
Gchq
Gchq cyberchef |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gchq:cyberchef:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gchq
Gchq cyberchef |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-29T02:56:14.260Z
Reserved: 2026-04-29T02:55:52.684Z
Link: CVE-2026-42615
No data.
Status : Received
Published: 2026-04-29T04:16:41.750
Modified: 2026-04-29T04:16:41.750
Link: CVE-2026-42615
No data.
OpenCVE Enrichment
Updated: 2026-04-29T04:30:02Z
Weaknesses