LOW3.5
GHSA-xfp8-x3j6-h67v
ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
Details
A cross-site scripting (XSS) issue exists in ExpressGateway ≤ 1.16.10 in lib/rest/routes/apps.js. User-controlled data returned by the REST endpoint is not sanitized before being rendered by the admin/UI layer, allowing an authenticated, low-privileged actor to store or reflect a payload that executes in a maintainer’s browser when the resource is viewed. The issue can be triggered remotely over the network and does not impact availability. No vendor fix is available at this time.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/express-gateway
Introduced in:
0No fixed version published yet for express-gateway (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-9096[ADVISORY]
- https://github.com/freshfish-hust/my-cves/issues/6[WEB]
- https://github.com/freshfish-hust/my-cves/issues/6#issue-3287078206[WEB]
- https://github.com/ExpressGateway/express-gateway[PACKAGE]
- https://vuldb.com/?ctiid.320418[WEB]
- https://vuldb.com/?id.320418[WEB]
- https://vuldb.com/?submit.627833[WEB]