CVE-2022-31160 is a cross-site scripting vulnerability in jQuery UI affecting versions prior to 1.13.2. The flaw occurs in the checkboxradio widget when it is initialized on an input element enclosed within a label element, causing the parent label contents to be treated as the input label. If the application later calls .checkboxradio("refresh") and the original label markup contains encoded HTML entities, those entities can be incorrectly decoded during the refresh process. This can transform attacker-controlled encoded markup into active HTML or script in the browser, resulting in script execution in the context of the affected page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2022-31160, a Cross-Site Scripting (XSS) vulnerability in jQuery UI's Checkboxradio widget (versions ≤ 1.13.1). The vulnerability arises when the widget's 'refresh' method decodes HTML entities in label content, potentially turning safely encoded malicious input into executable JavaScript. The repository is structured as a Node.js application with a Dockerfile for easy setup. The main files are: - `Dockerfile`: Sets up a Node.js 14-alpine environment, installs dependencies, and runs the server. - `server.js`: (not shown, but referenced) Likely an Express.js server that serves the demonstration HTML. - `simplified-survey.html`: Contains the vulnerable survey interface with multiple XSS payload scenarios. - `package.json` and dependencies: Standard Node.js/Express dependencies for serving the demo. The README provides detailed instructions for building and running the demo in Docker, and describes the vulnerability, attack vector, and test payloads. The main endpoints for demonstration are `http://localhost:3000/survey` and `http://localhost:3000/simplified-survey`. The exploit demonstrates three XSS scenarios (immediate and interactive) using different HTML elements and event handlers. This PoC is intended for educational and research purposes only, and does not include weaponized or automated exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.