---
id: CVE-2021-25313
aliases:
  - GHSA-6m8r-jh89-rq7h
title: Rancher Cross-site Scripting Vulnerability
summary: Rancher Cross-site Scripting Vulnerability
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: rancher
product: github.com/rancher/rancher
ecosystem: go
affected:
  - 'github.com/rancher/rancher >= 2.5.0, < 2.5.6'
  - 'github.com/rancher/rancher >= 2.4.0, < 2.4.14'
  - github.com/rancher/rancher < 2.3.11
patched:
  - github.com/rancher/rancher 2.5.6
  - github.com/rancher/rancher 2.4.14
  - github.com/rancher/rancher 2.3.11
published: '2022-05-24'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:20.451917571Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6m8r-jh89-rq7h'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-25313'
  - url: 'https://github.com/rancher/rancher/issues/31583'
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1181852'
  - url: 'https://github.com/rancher/rancher/releases/tag/v2.3.11'
  - url: 'https://github.com/rancher/rancher/releases/tag/v2.4.14'
  - url: 'https://github.com/rancher/rancher/releases/tag/v2.5.6'
tags:
  - osv
  - go
epss: 0.01498
epssPercentile: 0.73117
ingestedAt: '2026-07-11T18:57:04.514Z'
---

## Overview

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.

## Affected packages

- `github.com/rancher/rancher >= 2.5.0, < 2.5.6`
- `github.com/rancher/rancher >= 2.4.0, < 2.4.14`
- `github.com/rancher/rancher < 2.3.11`

## Remediation

Upgrade to a patched release:

- `github.com/rancher/rancher 2.5.6`
- `github.com/rancher/rancher 2.4.14`
- `github.com/rancher/rancher 2.3.11`
