Skip to content

[GHSA-ch4j-vcf5-58x5] Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option - #9297

Open
kgnio wants to merge 1 commit into
kgnio/advisory-improvement-9297from
kgnio-GHSA-ch4j-vcf5-58x5
Open

[GHSA-ch4j-vcf5-58x5] Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option#9297
kgnio wants to merge 1 commit into
kgnio/advisory-improvement-9297from
kgnio-GHSA-ch4j-vcf5-58x5

Conversation

@kgnio

@kgnio kgnio commented Sep 1, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
The advisory identifies Cockpit CMS through version 2.14.0 as affected, but the structured metadata does not identify the first patched release.

The advisory references upstream fix commit 72a83fcfe85ad8330e9ae834bc02fa517b5749e9. Cockpit CMS 2.14.1 was subsequently released and contains this fix.

The upstream 2.14.1 release notes explicitly include the replacement of the Function-based interpolation logic and sanitization of Set field display template output to prevent stored XSS.

This change adds:

Patched version: 2.14.1

The existing affected version range is unchanged.

No other advisory metadata is changed.

References:

@github-actions
github-actions Bot changed the base branch from main to kgnio/advisory-improvement-9297 September 1, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant