—
GO-2026-4277
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk
Quick fix
GO-2026-4277 — github.com/knadh/listmonk: upgrade to the fixed version with the command below.
go get github.com/knadh/listmonk@v1.1.1-0.20251231125615-74dc5a01cfbbDetails
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/knadh/listmonk
Introduced in:
0Fixed in: 1.1.1-0.20251231125615-74dc5a01cfbbFix
go get github.com/knadh/listmonk@v1.1.1-0.20251231125615-74dc5a01cfbb