GHSA-gcpq-mrgg-v5f3

Suggest an improvement
Source
https://github.com/advisories/GHSA-gcpq-mrgg-v5f3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gcpq-mrgg-v5f3/GHSA-gcpq-mrgg-v5f3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gcpq-mrgg-v5f3
Aliases
  • CVE-2018-25157
Published
2026-02-11T15:30:27Z
Modified
2026-02-11T19:11:16Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Phraseanet vulnerable to stored cross-site scripting through crafted file names
Details

Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-11T18:39:48Z",
    "nvd_published_at":  "2026-02-11T15:16:07Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / phraseanet/phraseanet

Package

Name
phraseanet/phraseanet
Purl
pkg:composer/phraseanet/phraseanet

Affected ranges

Affected versions

4.*
4.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gcpq-mrgg-v5f3/GHSA-gcpq-mrgg-v5f3.json"