diff --git a/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json b/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json new file mode 100644 index 00000000000..a880c6083c8 --- /dev/null +++ b/advisories/github-reviewed/2025/06/GHSA-4xg4-54hm-9j77/GHSA-4xg4-54hm-9j77.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xg4-54hm-9j77", + "modified": "2025-06-03T06:27:28Z", + "published": "2025-06-03T06:27:28Z", + "aliases": [ + "CVE-2025-48495" + ], + "summary": "Gokapi has stored XSS vulnerability in friendly name for API keys", + "details": "### Impact\n\nBy renaming the friendly name of an API key, an authenticated user could inject JS into the API key overview, which would also be executed when another user clicks on his API tab.\nWith the affected versions