CVE-2023-5654 describes an arbitrary URL fetching vulnerability in the React Developer Tools extension, affecting facebook react-devtools. The flaw allows any webpage to trigger the extension to fetch unvalidated URLs, potentially leading to information disclosure or other impacts. Rated Medium severity (CVSS 6.5), it has a network attack vector and low attack complexity, with potential for limited integrity and availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.28.4CPE matchmatch criteria | cpe:2.3:a:facebook:react-devtools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.