GHSA-26gq-grmh-6xm6: Gogs vulnerable to Stored XSS via Mermaid diagrams
Stored XSS via mermaid diagrams due to usage of vulnerable renderer library
References
- github.com/advisories/GHSA-26gq-grmh-6xm6
- github.com/gogs/gogs
- github.com/gogs/gogs/commit/71a72a72ad1c8cea7940c9d7e4cbdfbc0fc3d401
- github.com/gogs/gogs/security/advisories/GHSA-26gq-grmh-6xm6
- github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh
- github.com/mermaid-js/mermaid/security/advisories/GHSA-8gwm-58g9-j8pw
Code Behaviors & Features
Detect and mitigate GHSA-26gq-grmh-6xm6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →