PT-2024-29883 · Galaxy · Galaxy

Partywavesec

·

Published

2024-09-20

·

Updated

2025-08-15

·

CVE-2024-42346

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Galaxy versions prior to the latest patched version
Description The issue concerns the editor visualization, specifically the "/visualizations" endpoint, which can be used to store HTML tags and trigger javascript execution upon an edit operation. Users are advised to upgrade as there are no known workarounds for this issue.
Recommendations For all affected versions of Galaxy, upgrade to the latest version that includes the supplied patches to resolve the issue. As a temporary workaround, consider restricting access to the "/visualizations" endpoint until the upgrade is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-42346
GHSA-X6W7-3GWF-QR9R
PYSEC-2024-272
PYSEC-2024-273

Affected Products

Galaxy