CVE-2025-53624 - CVE House
Back to Database
Status published Critical CVE-2025-53624

docusaurus-plugin-content-gists Exposes GitHub Personal Access Token

Vulnerability Description

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token, intended for build-time API access only, is inadvertently included in client-side JavaScript bundles, making it accessible to anyone who can view the website's source code. This vulnerability is fixed in 4.0.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53624

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

webbertakken

View all reports →

Affected Software

docusaurus-plugin-content-gists
Vulnerable Versions:
< 4.0.0

Timeline

Official Publish: July 9th, 2025
Last Modified: July 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)