A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
History

Wed, 27 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Blitzjs
Blitzjs blitz
Vendors & Products Blitzjs
Blitzjs blitz

Tue, 26 May 2026 02:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title blitz-js blitz Sign-in LoginForm.tsx cross site scripting
First Time appeared Blitz-js
Blitz-js blitz
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:blitz-js:blitz:*:*:*:*:*:*:*:*
Vendors & Products Blitz-js
Blitz-js blitz
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-05-26T01:30:09.761Z

Updated: 2026-05-27T19:59:37.342Z

Reserved: 2026-05-25T19:12:43.499Z

Link: CVE-2026-9520

cve-icon Vulnrichment

Updated: 2026-05-27T19:59:33.438Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T02:16:40.823

Modified: 2026-05-26T19:54:40.357

Link: CVE-2026-9520

cve-icon Redhat

No data.