{"id":"CVE-2019-1010261","aliases":["GHSA-5rh7-6gfj-mc87","GO-2023-1922"],"url":"https://o3.security/vulnerability/CVE-2019-1010261","summary":"Gitea XSS Vulnerability","details":"Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must open a specifically crafted URL. The fixed version is: 1.7.1 and later.","published":"2019-07-18T17:15:11.647Z","modified":"2026-08-07T14:59:52.855274Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"code.gitea.io/gitea","fixedVersion":"1.7.1"}],"fix":{"url":"https://github.com/go-gitea/gitea/pull/5905","label":"go-gitea/gitea#5905"},"references":[{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/5905"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:59:52.855274Z"}}