{"id":"CVE-2025-24978","aliases":["GHSA-g8rh-fjm6-h2h9","GO-2026-6446"],"title":"LF Edge eKuiper: Self-XSS in External Service Creation","summary":"LF Edge eKuiper: Self-XSS in External Service Creation","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","vendor":"lf-edge","product":"github.com/lf-edge/ekuiper/v2","ecosystem":"go","affected":["github.com/lf-edge/ekuiper/v2 < 2.4.0"],"patched":["github.com/lf-edge/ekuiper/v2 2.4.0"],"published":"2026-09-09","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:40:43.036491822Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g8rh-fjm6-h2h9","references":[{"url":"https://github.com/lf-edge/ekuiper/security/advisories/GHSA-g8rh-fjm6-h2h9"},{"url":"https://github.com/lf-edge/ekuiper"},{"url":"https://github.com/lf-edge/ekuiper/releases/tag/v2.4.0"},{"url":"https://github.com/advisories/GHSA-g8rh-fjm6-h2h9"}],"tags":["osv","go","ghsa"],"cwe":["CWE-79"],"ingestedAt":"2026-09-09T18:17:58.315Z","slug":"CVE-2025-24978","body":"## Overview\n\n### Summary\nA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.\n\n### Details\nPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as `<iframe src=\"...\">`). If an administrative web UI rendered the unescaped service name, arbitrary script execution could occur in the context of the user's browser session.\n\n### PoC\n1. Create an external service JSON definition with a filename containing an XSS payload, e.g. `<iframe src=\"javascript:alert`1337`\">.json` inside a ZIP archive.\n2. In external service creation, upload the ZIP and provide the matching service name: `<iframe src=\"javascript:alert`1337`\">`.\n3. Upon service registration, the unescaped name executes when rendered in the UI context.\n\n### Impact\nSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session.\n\n### Remediation & Patches\n- **Upgrade to eKuiper >= 2.4.0**: Strict alphanumeric identifier validation (`validate.ValidateID`) is now enforced on all external service creation and update endpoints, rejecting invalid characters.\n\n### Workarounds\n- Protect eKuiper management endpoints (`POST /services`) with authentication and network-level firewalls.\n\n### Credits\n- Reported by Alexey Kosmachev, Bi.Zone (@TheMostKnown)\n\n## Affected packages\n\n- `github.com/lf-edge/ekuiper/v2 < 2.4.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/lf-edge/ekuiper/v2 2.4.0`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}