Gokapi has Stored XSS in SVG Hotlinks
Package
Affected versions
< 2.2.3
Patched versions
2.2.3
Description
Published to the GitHub Advisory Database
Mar 5, 2026
Reviewed
Mar 5, 2026
Published by the National Vulnerability Database
Mar 6, 2026
Last updated
Mar 8, 2026
Summary
If a malicious authenticated user uploads SVG and creates a hotlink for it, they achieve stored XSS.
Details
The hotlinking functionality fails to properly handle scripts included in the SVGs, allowing authenticated attackers with the ability to upload and hotlink file to execute arbitrary JS.
Issue found by aisafe.io
Impact
Authenticated attackers with the ability to upload and hotlink files can execute arbitrary JavaScript.
References