Harbor's repository description page allows for XSS
Vulnerability Description
Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32019
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/goharbor/harbor/security/advisories/GHSA-f9vc-vf3r-pqqq
- https://github.com/goharbor/harbor/commit/76c2c5f7cfd9edb356cbb373889a59cc3217a058
- https://github.com/goharbor/harbor/commit/a13a16383a41a8e20f524593cb290dc52f86f088
- https://github.com/goharbor/harbor/commit/f019430872118852f83f96cac9c587b89052d1e5
Affected Vendor
goharbor
View all reports →