{"id":"CVE-2025-24978","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-24978","summary":"LF Edge eKuiper: Self-XSS in External Service Creation","details":"### Summary\nA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.\n\n### Details\nPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as `<iframe src=\"...\">`). If an administrative web UI rendered the unescaped service name, arbitrary script execution could occur in the context of the user's browser session.\n\n### PoC\n1. Create an external service JSON definition with a filename containing an XSS payload, e.g. `<iframe src=\"javascript:alert`1337`\">.json` inside a ZIP archive.\n2. In external service creation, upload the ZIP and provide the matching service name: `<iframe src=\"javascript:alert`1337`\">`.\n3. Upon service registration, the unescaped name executes when rendered in the UI context.\n\n### Impact\nSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session.\n\n### Remediation & Patches\n- **Upgrade to eKuiper >= 2.4.0**: Strict alphanumeric identifier validation (`validate.ValidateID`) is now enforced on all external service creation and update endpoints, rejecting invalid characters.\n\n### Workarounds\n- Protect eKuiper management endpoints (`POST /services`) with authentication and network-level firewalls.\n\n### Credits\n- Reported by Alexey Kosmachev, Bi.Zone (@TheMostKnown)","published":"2026-09-09T17:56:22Z","modified":"2026-09-09T18:10:59.937481Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/lf-edge/ekuiper/v2","fixedVersion":"2.4.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/lf-edge/ekuiper/security/advisories/GHSA-g8rh-fjm6-h2h9"},{"type":"PACKAGE","url":"https://github.com/lf-edge/ekuiper"},{"type":"WEB","url":"https://github.com/lf-edge/ekuiper/releases/tag/v2.4.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T18:10:59.937481Z"}}