Podinfo affected by Arbitrary File Upload that leads to Stored Cross-Site Scripting (XSS)
Low severity
GitHub Reviewed
Published
Feb 3, 2026
to the GitHub Advisory Database
•
Updated Mar 16, 2026
Package
Affected versions
<= 1.8.1-0.20250515093358-fb3b01be30a3
Patched versions
1.8.1-0.20260314125853-83deb7fcb742
Description
Published by the National Vulnerability Database
Feb 3, 2026
Published to the GitHub Advisory Database
Feb 3, 2026
Reviewed
Feb 3, 2026
Last updated
Mar 16, 2026
Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).
References