GHSA-q23m-vm9r-5745MediumCVSS 5.4

podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints

Published
May 14, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served as text/html due to Go's content type detection, allowing the reflected script to execute in the podinfo origin context when victims visit the attacker's page.

🎯 Affected products1

  • go/github.com/stefanprodan/podinfo:< 1.8.1-0.20260519111337-cbebb20fd485

🔗 References (8)