PT-2024-36066 · Microsoft · Nuget Gallery
Lyndaidaii
·
Published
2024-12-06
·
Updated
2025-09-05
·
CVE-2024-54138
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
NuGet Gallery versions prior to 2024.12.06
Description:
The NuGet Gallery has a security issue related to its handling of autolinks in Markdown content. Although the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allows attackers to exploit autolinks as a vector for Cross-Site Scripting (XSS) attacks.
Recommendations:
For versions prior to 2024.12.06, update to a version released on or after 2024.12.06 to resolve the issue. As a temporary workaround, consider disabling the handling of autolinks in Markdown content until a patch is available. Restrict access to Markdown content with autolinks to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuget Gallery