PT-2026-55285 · Netdata · Netdata
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Netdata versions prior to 2.3.1
Description
Reflected cross-site scripting occurs when the application reflects the user-supplied
love query parameter of the 'api/v2/ilove.svg' and 'api/v3/ilove.svg' endpoints verbatim into a generated SVG document without HTML or XML escaping. The response is served with the Content-Type image/svg+xml, allowing an attacker to execute arbitrary scripts in the victim's browser within the origin of the instance. These endpoints are registered with HTTP ACL NOCHECK and allow anonymous access, meaning they are reachable without authentication on a default agent because bearer-token protection is disabled by default.Recommendations
Update to version 2.3.1 or later.
As a temporary workaround, restrict access to the 'api/v2/ilove.svg' and 'api/v3/ilove.svg' endpoints.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netdata