CVE-2025-68467: Dark Reader gives users the ability to request style sheets from local web servers
(updated )
Dark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example http://localhost:8080/style.css, If an address was available and returned a text/css content type.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-68467 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →