---
id: CVE-2025-24978
aliases:
  - GHSA-g8rh-fjm6-h2h9
  - GO-2026-6446
title: 'LF Edge eKuiper: Self-XSS in External Service Creation'
summary: 'LF Edge eKuiper: Self-XSS in External Service Creation'
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'
vendor: lf-edge
product: github.com/lf-edge/ekuiper/v2
ecosystem: go
affected:
  - github.com/lf-edge/ekuiper/v2 < 2.4.0
patched:
  - github.com/lf-edge/ekuiper/v2 2.4.0
published: '2026-09-09'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:40:43.036491822Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-g8rh-fjm6-h2h9'
references:
  - url: 'https://github.com/lf-edge/ekuiper/security/advisories/GHSA-g8rh-fjm6-h2h9'
  - url: 'https://github.com/lf-edge/ekuiper'
  - url: 'https://github.com/lf-edge/ekuiper/releases/tag/v2.4.0'
  - url: 'https://github.com/advisories/GHSA-g8rh-fjm6-h2h9'
tags:
  - osv
  - go
  - ghsa
cwe:
  - CWE-79
ingestedAt: '2026-09-09T18:17:58.315Z'
---

## Overview

### Summary
A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.

### Details
Prior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as `<iframe src="...">`). If an administrative web UI rendered the unescaped service name, arbitrary script execution could occur in the context of the user's browser session.

### PoC
1. Create an external service JSON definition with a filename containing an XSS payload, e.g. `<iframe src="javascript:alert`1337`">.json` inside a ZIP archive.
2. In external service creation, upload the ZIP and provide the matching service name: `<iframe src="javascript:alert`1337`">`.
3. Upon service registration, the unescaped name executes when rendered in the UI context.

### Impact
Self-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session.

### Remediation & Patches
- **Upgrade to eKuiper >= 2.4.0**: Strict alphanumeric identifier validation (`validate.ValidateID`) is now enforced on all external service creation and update endpoints, rejecting invalid characters.

### Workarounds
- Protect eKuiper management endpoints (`POST /services`) with authentication and network-level firewalls.

### Credits
- Reported by Alexey Kosmachev, Bi.Zone (@TheMostKnown)

## Affected packages

- `github.com/lf-edge/ekuiper/v2 < 2.4.0`

## Remediation

Upgrade to a patched release:

- `github.com/lf-edge/ekuiper/v2 2.4.0`
