Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89f7-r7x8-83q7

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7

Описание

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content.

Since SVG files can contain embedded JavaScript, an attacker can upload a malicious SVG that executes arbitrary JavaScript when viewed by other users, leading to stored cross-site scripting (XSS). This allows stealing authentication tokens stored in cookies, including JWT access and refresh tokens.

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content.

Since SVG files can contain embedded JavaScript, an attacker can upload a malicious SVG that executes arbitrary JavaScript when viewed by other users, leading to stored cross-site scripting (XSS). This allows stealing authentication tokens stored in cookies, including JWT access and refresh tokens.

EPSS

Процентиль: 22%
0.00072
Низкий

7 High

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
12 дней назад

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. Since SVG files can contain embedded JavaScript, an attacker can upload a malicious SVG that executes arbitrary JavaScript when viewed by other users, leading to stored cross-site scripting (XSS). This allows stealing authentication tokens stored in cookies, including JWT access and refresh tokens.

EPSS

Процентиль: 22%
0.00072
Низкий

7 High

CVSS4

Дефекты

CWE-79