{"id":"CVE-2024-9427","aliases":["GHSA-g2vg-8hfg-79vj","PYSEC-2026-1501"],"title":"Koji Cross-site Scripting","summary":"Koji Cross-site Scripting","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","vendor":"koji","product":"koji","ecosystem":"pip","affected":["koji >= 1.35.0, < 1.35.1","koji >= 1.34.0, < 1.34.3","koji < 1.33.2"],"patched":["koji 1.35.1","koji 1.34.3","koji 1.33.2"],"published":"2024-12-24","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g2vg-8hfg-79vj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9427"},{"url":"https://access.redhat.com/security/cve/CVE-2024-9427"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2316047"},{"url":"https://docs.pagure.org/koji/CVEs/CVE-2024-9427"},{"url":"https://pagure.io/koji"},{"url":"https://pagure.io/koji/c/8c72d90d7bb991f8fb193851b80847ac9e9474a4?branch=master"}],"tags":["osv","pip"],"epss":0.00296,"epssPercentile":0.22458,"ingestedAt":"2026-07-08T18:25:49.187Z","slug":"CVE-2024-9427","body":"## Overview\n\nA vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code.\n\n## Affected packages\n\n- `koji >= 1.35.0, < 1.35.1`\n- `koji >= 1.34.0, < 1.34.3`\n- `koji < 1.33.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `koji 1.35.1`\n- `koji 1.34.3`\n- `koji 1.33.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}