LOW 3.7 GitHub
CVE-2025-24978
LF Edge eKuiper: Self-XSS in External Service Creation
### Summary
A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.
### Details
Prior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name co
Affected Products
- go/github.com/lf-edge/ekuiper/v2 < 2.4.0
References
- https://github.com/advisories/GHSA-g8rh-fjm6-h2h9
- https://github.com/lf-edge/ekuiper/security/advisories/GHSA-g8rh-fjm6-h2h9
- https://github.com/lf-edge/ekuiper/releases/tag/v2.4.0
- https://github.com/advisories/GHSA-g8rh-fjm6-h2h9
This low severity vulnerability with a CVSS score of 3.7 was published on 2026-09-09 via GitHub. Affected: go/github.com/lf-edge/ekuiper/v2 < 2.4.0.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.