We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32019

Harbor's repository description page allows for XSS



Description

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.

Reserved 2025-04-01 | Published 2025-07-23 | Updated 2025-07-23 | Assigner GitHub_M


MEDIUM: 4.1CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 2.12.0-rc1, < 2.12.4-rc1
affected

>= 2.13.0-rc1, < 2.13.1-rc1
affected

<= 2.4.0-rc1.1, < 2.11.3
affected

References

github.com/...harbor/security/advisories/GHSA-f9vc-vf3r-pqqq

github.com/...ommit/76c2c5f7cfd9edb356cbb373889a59cc3217a058

github.com/...ommit/a13a16383a41a8e20f524593cb290dc52f86f088

github.com/...ommit/f019430872118852f83f96cac9c587b89052d1e5

cve.org (CVE-2025-32019)

nvd.nist.gov (CVE-2025-32019)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32019

Support options

Helpdesk Chat, Email, Knowledgebase