{"id":"CVE-2024-53257","aliases":["GHSA-7mwh-q3xm-qh6p","GO-2024-3306"],"url":"https://o3.security/vulnerability/CVE-2024-53257","summary":"Vitess allows HTML injection in /debug/querylogz & /debug/env","details":"### Summary\n\nThe `/debug/querylogz` and `/debug/env` pages for `vtgate` and `vttablet` do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will.\n\n### Details\n\nThese pages are rendered using `text/template` instead of rendering with a proper HTML templating engine.\n\n### PoC\n\nExecute any query where part of it is HTML markup, for example as part of a string. To make it easier to observe you might want to make sure the query takes a few seconds to complete, giving you time to refresh the status page. \n\nExample query that can trigger the issue:\n\n```sql\nUPDATE users\nSET\n    email = CONCAT(\"<img src=https://cataas.com/cat/says/oops>\", users.idUser, \"@xxx\")\nWHERE\n    email NOT LIKE '%xxx%' AND email != \"demo@xxx.com\"\n```\n\nResult: \n\n![image](https://github.com/user-attachments/assets/c583816b-157c-474e-bbed-152b3dc0372f)\n\n### Impact\n\nAnyone looking at the Vitess status page is affected. This would normally be owners / administrators of the Vitess cluster.\n\nAnyone that can influence what text show up in queries can trigger it. This would normally be pretty much everybody interacting with a system that uses Vitess as a backend.","published":"2024-12-03T15:46:40.513Z","modified":"2026-08-12T03:51:33.389729738Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00428,"percentile":0.35944,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"vitess.io/vitess","fixedVersion":"0.21.1"},{"ecosystem":"Go","name":"vitess.io/vitess","fixedVersion":"0.20.4"},{"ecosystem":"Go","name":"vitess.io/vitess","fixedVersion":"0.19.8"}],"fix":{"url":"https://github.com/vitessio/vitess/commit/2b71d1b5f8ca676beeab2875525003cd45096217","label":"vitessio/vitess@2b71d1b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53257.json"},{"type":"ADVISORY","url":"https://github.com/vitessio/vitess/security/advisories/GHSA-7mwh-q3xm-qh6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53257"},{"type":"FIX","url":"https://github.com/vitessio/vitess/commit/2b71d1b5f8ca676beeab2875525003cd45096217"},{"type":"PACKAGE","url":"https://github.com/vitessio/vitess"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.389729738Z"}}