Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-g8rh-fjm6-h2h9
Summary
A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.
Details
Prior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as <iframe src="...">). If an administrative web UI rendered the unescaped service name, arbitrary script execution could occur in the context of the user's browser session.
PoC
- Create an external service JSON definition with a filename containing an XSS payload, e.g.
<iframe src="javascript:alert1337">.jsoninside a ZIP archive. - In external service creation, upload the ZIP and provide the matching service name:
<iframe src="javascript:alert1337">. - Upon service registration, the unescaped name executes when rendered in the UI context.
Impact
Self-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session.
Remediation & Patches
- Upgrade to eKuiper >= 2.4.0: Strict alphanumeric identifier validation (
validate.ValidateID) is now enforced on all external service creation and update endpoints, rejecting invalid characters.
Workarounds
- Protect eKuiper management endpoints (
POST /services) with authentication and network-level firewalls.
Credits
- Reported by Alexey Kosmachev, Bi.Zone (@TheMostKnown)
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is difficult for an attacker to exploit this vulnerability and may require special conditions. An attacker needs basic access or low-level privileges. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a low impact on the confidentiality of the information. There is a low impact on the integrity of the data.
Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.
Probability that this vulnerability will be exploited in the wild within the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
- CVE-2025-24978Alias
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard