FlawAtlas
Search the atlas
CVE-2025-32019 Moderate

Harbor repository description page has Cross-site Scripting vulnerability in github.com/goharbor/harbor

Harbor repository description page has Cross-site Scripting vulnerability in github.com/goharbor/harbor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/goharbor/harbor before v2.4.0-rc1.0.20250421072404-a13a16383a41.

Exploit probability 0.3%
Published July 29, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

16 explicit affected versions

Bitnami harbor
Go github.com/goharbor/harbor
Go github.com/goharbor/harbor

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-harbor-2025-32019

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0 and 2.13.0, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.

View original source
Open Source Vulnerabilities GO-2025-3825

Harbor repository description page has Cross-site Scripting vulnerability in github.com/goharbor/harbor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/goharbor/harbor before v2.4.0-rc1.0.20250421072404-a13a16383a41.

View original source
Open Source Vulnerabilities GHSA-f9vc-vf3r-pqqq

### Impact In the Harbor repository information, it is possible to inject code resulting in a stored XSS issue. ### Patches Harbor v2.12.3 Harbor 2.11.3 ### Workarounds No ### References ### Credit [email protected]

View original source
Open Source Vulnerabilities CVE-2025-32019

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.

View original source

05 / REFERENCES

Further evidence