Home
MEDIUM: 5.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
2023.0.0 (custom) before 2025.4.10678
affected
2026.1.0 (custom) before 2026.1.11451
affected
2026.2.0 (custom) before 2026.2.13114
affected
Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
Problem types
Stored XSS using artifacts
Product status
2023.0.0 (custom) before 2025.4.10678
2026.1.0 (custom) before 2026.1.11451
2026.2.0 (custom) before 2026.2.13114
Credits
This vulnerability was found by asotyc
References
advisories.octopus.com/post/2026/sa2026-05