-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/alist-org/alist/v3 | go | <= 3.5.1 |
The vulnerability exists in bulletin board functionality. XSS typically occurs when: 1) Input handlers fail to sanitize user content (controller functions), and 2) Template rendering lacks proper escaping (view layer). While exact code isn't available, these are common patterns in Go web apps. The medium confidence reflects the lack of direct code evidence, but aligns with the described attack vector and CWE-79 characteristics.
Ongoing coverage of React2Shell