VDB
KO
MEDIUM 6.5

GHSA-x4f6-mqg6-28xx

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Quick fix

GHSA-x4f6-mqg6-28xx — github.com/apache/incubator-answer: upgrade to the fixed version with the command below.

go get github.com/apache/incubator-answer@v1.7.2-0.20260511040518-11091244f64e

Details

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/apache/incubator-answer
Introduced in: 0 Fixed in: 1.7.2-0.20260511040518-11091244f64e
Fix go get github.com/apache/incubator-answer@v1.7.2-0.20260511040518-11091244f64e

References