hunt-xss

Installation
SKILL.md

Crown Jewel Targets

XSS is the highest-frequency web bug class but the modern paying surface has shifted. Reflected XSS on a public marketing page is mid four-figure at best; stored XSS chained to admin ATO is mid five-figure; mXSS bypass of a popular sanitizer pays direct from Cure53/Snyk plus downstream chains. The 24-month meta has crystallized around six asset types. All CVEs below are NVD-verified.

1. DOMPurify mXSS bypass family (high four-figure to mid five-figure direct + thousands of downstream chains). Every DOMPurify bypass disclosed since 2024 has cascaded through every consumer that hadn't pinned to the latest version. CVE-2024-47875 (GHSA-gx9m-whjm-85jf, Oct 2024, GitHub CVSS 10.0) — nesting-based mXSS by @IcesFont via cure53berlin disclosure. Versions <2.5.0 and <3.1.3 vulnerable. CVE-2024-45801 (GHSA-mmhx-hmjr-r674) — companion depth-bypass weakened by prototype pollution; backport reference. GHSA-h8r8-wccr-v5f2 — DOMPurify mXSS via Re-Contextualization in 3.3.1 (Oscar Uribe / Camilo Vera / Cristian Vargas, Fluid Attacks Research) — sanitized output reinserted via innerHTML into a wrapper (script, xmp, iframe, noembed, noframes, noscript) mutates during second parse. Yaniv Nizry @YNizry Dec 2024 — DOMPurify 3.2.1 non-default-config bypass via is attribute mishandling. @kinugawamasato deep-nesting variant — works on Firefox + Chromium + Safari (most other mXSS techniques only work on one browser). @hash_kitten HTML insertion modes bypass — full bypass without nesting. @ryotkak XML-based bypass. The mizu.re writeup at https://mizu.re/post/exploring-the-dompurify-library-bypasses-and-fixes is the canonical recent reference. Hunt every DOMPurify consumer that hasn't pinned to current; pays per-target.

2. Modern JS / RSC / Server Actions content rendering (low to mid five-figure). Next.js Server Components and Server Functions deserialize and render client-supplied content. The DoS family (CVE-2025-67779, CVE-2025-55184, GHSA-5j59-xgg2-r9c4 published Dec 11, 2025) demonstrates that the RSC runtime trusts payload structure; the same trust surface produces XSS when RSC payloads or Server Action responses round-trip through dangerouslySetInnerHTML or React's HTML escape boundary. Affects React 19.0.0/19.1.0/19.1.1/19.2.0 with react-server-dom-webpack / parcel / turbopack; patches in React 19.0.2/19.1.3/19.2.2 and Next.js 14.2.35 / 15.x point releases / 16.0.10. The Vercel Platform Protection WAF program pays for new bypass primitives.

3. OAuth redirect_uri / returnTo XSS (low five-figure on enterprise SaaS). CVE-2025-67716 (GHSA-mr6f-h57v-rpj5, Dec 10 2025) — Auth0 Next.js SDK <4.13.0 — returnTo parameter input-validation flaw lets attackers inject unintended OAuth query parameters into the authorization request. Disclosed by Joshua Rogers / @MegaManSec via Okta. The pattern: any OAuth library that takes redirect_uri / returnTo / state / RelayState (SAML) and reflects it back into HTML (error page, success page, logout page) without proper escaping. The HackerOne TopOAuth list (reddelexc/hackerone-reports/blob/master/tops_by_bug_type/TOPOAUTH.md) has dozens of disclosed cases — Reflected XSS at oauth2/fallbacks/error against Zomato/ORY Hydra, XSS at OAuth authorize/authenticate against X/xAI, XSS in OAuth Redirect Url at Dropbox, Stored XSS in OAuth redirect URI at Nextcloud, OAuth redirect_uri bypass via IDN homograph at Semrush (bounty $0 as the program disclosed it informational — but the technique generalizes; HackerOne disclosed write-up).

4. postMessage XSS with origin-check bypass (mid four-figure to low five-figure on banking / fintech / chat-widget integrations). Almost every postMessage implementation has at least one of these problems: no origin check, broken origin check (includes() instead of ===), trusts message data without sanitization. CleverTap Web SDK <=1.15.2 issue #424 (Mr-Neutr0n, Jun 2025)event.origin checked with .includes() allowing bypass via dashboard.clevertap.com.attacker.com; display.details[0].html field assigned to element.innerHTML without filtering. Bug Bounty Playbook documents this as the dominant chat-widget integration pattern: vendor's domain has its own XSS, attacker uses it to send crafted messages that pass the bank's origin check, executing in banking session context. Hunt every addEventListener('message', ...) in every JS bundle.

5. Stored XSS → Admin Account Takeover via shared-content features (mid four-figure to mid five-figure). GHSA-jmr4-p576-v565 (listmonk, Jan 2 2026, CVSS 8.0) — campaign-management user injects XSS payload into newsletter draft, super-admin reviews → backdoor admin created. Weaponized via public archive feature — victim simply visits link, no preview click required. Pattern repeats across CMS, mailers, ticketing systems, support tools where lower-privileged content reaches higher-privileged viewers. Apple Discussions Stored XSS — $5,000 bounty disclosed via Apple Security Bounty program May-Jul 2025, ZombieHack writeup at https://medium.com/@ZombieHack/apple-developer-stored-xss-5-000-bounty-writeup-2025-cc34a030a5bf — discussions.apple.com initial XSS, partial fix bypassed, re-enabled across mirrors and developer.apple.com/forums; Apple acknowledged, broader fix.

6. Markdown / wiki / comment renderer XSS. CVE-2024-21535 (markdown-to-jsx <7.4.0)src property iframe injection. Markdown renderers and their plugin ecosystems are systematically under-audited because devs trust the "markdown sanitizes HTML" assumption. Reference: gregxsunday's "$3,133.70 XSS in golang's net/html library" — disclosed via Google bug bounty program for finding XSS in the parser the renderer depends on, not the renderer itself. Hunt every wiki/comment/issue-tracker/chat that supports markdown formatting.

7. Rich-text editor XSS — Trix family (mid four-figure to low five-figure). Trix is the rich-text editor shipped by Basecamp / 37signals and embedded across many SaaS (Basecamp itself, HEY, plus many ActionText-using Rails apps). Trix Editor 2.1.8 Mutation-Based Stored XSS — H1 report 2819573 (2025 Critical). Trix Editor 2.1.1 Stored XSS — H1 report 2521419 (2024 High). Pattern: rich-text editors store HTML structure including attachment/embed metadata; sanitizer-vs-renderer mismatch produces mXSS on render. Same class hits CKEditor, TinyMCE, Quill, Slate, Lexical when consumers don't pin to current versions. Hunt every rich-text editor instance for: attachment-tag injection, embed-figure manipulation, paste-from-Word residue, drag-and-drop HTML smuggling.

8. Jupyter / data-science notebook XSS (mid four-figure to low five-figure on data-science platforms). GHSA-rch3-82jr-f9w9 (Jupyter Notebook 7.0.0-7.5.5 / JupyterLab through 4.5.6, CVSS 8.4 High) — CommandLinker XSS in malicious notebook files steals authentication tokens enabling REST API ATO. H1 report 1409788 (2022) — Arbitrary POST request as victim user from HTML injection in Jupyter notebooks. Notebook file (.ipynb) is JSON with cells containing user-controlled markdown/HTML rendered by the Jupyter frontend. Hunt: Jupyter Hub instances, Google Colab-style platforms, Hex / Deepnote / Databricks notebooks, ML platforms with notebook UI, any "share this notebook" feature.

Installs
17
GitHub Stars
812
First Seen
May 10, 2026
hunt-xss — h-mmer/pentest-agents