GHSA-6qwm-5fm9-cvjx

Suggest an improvement
Source
https://github.com/advisories/GHSA-6qwm-5fm9-cvjx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6qwm-5fm9-cvjx/GHSA-6qwm-5fm9-cvjx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6qwm-5fm9-cvjx
Aliases
Published
2026-06-09T09:32:07Z
Modified
2026-08-18T15:11:22Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Apache Answer vulnerable to Cross-site Scripting
Details

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-80"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-31T15:53:22Z",
    "nvd_published_at": "2026-06-09T09:16:29Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/apache/incubator-answer

Package

Name
github.com/apache/incubator-answer
View open source insights on deps.dev
Purl
pkg:golang/github.com/apache/incubator-answer

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.2-0.20260509080709-d1a4092c61cc

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6qwm-5fm9-cvjx/GHSA-6qwm-5fm9-cvjx.json"