ui is vulnerable to Cross-Site Scripting (XSS)
74
High Risk
Kestra's namespace file deletion dialog passes a user supplied file name to Vue's v-html directive without escaping. The backend returns those names and vue-i18n interpolation uses HTML without escaping, so markup in a file name executes as script when another user opens the delete dialog. Files uploaded through the UploadFiles plugin during a flow run can put those names into other namespaces. The fix escapes the file name before inserting it into the page.
You are affected if you are using a version that falls within the vulnerable range and a user can create or upload namespace files whose names are shown to other users.
ui is vulnerable to Cross-Site Scripting (XSS) in versions 0.21.19 - 1.3.35.
Upgrade the io.kestra:ui library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.