VDB
Sign up
—

GO-2026-5804

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing in github.com/umputun/remark42

Quick fix

GO-2026-5804 — github.com/umputun/remark42: upgrade to the fixed version with the command below.

go get github.com/umputun/remark42@v1.16.0

Details

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing in github.com/umputun/remark42

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/umputun/remark42
Introduced in: 1.6.0Fixed in: 1.16.0
Fixgo get github.com/umputun/remark42@v1.16.0

References