-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from uncontrolled rendering of external images. Analysis focused on: 1) Content processing functions that handle user-submitted images 2) Rendering functions that generate HTML output 3) The security control gap mentioned in the patch description about adding admin settings. While exact commit details are unavailable, the pattern matches CWE-495 through unintended exposure via rendering paths. Functions were identified based on typical Go web app patterns and the described mitigation of adding policy checks for external content.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/apache/answer | go | < 1.4.5 | 1.4.5 |
Ongoing coverage of React2Shell