PT-2025-1668 · Authentik · Authentik

Daniel Basta

·

Published

2025-02-04

·

Updated

2026-04-16

·

CVE-2024-11623

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Authentik versions prior to 2024.10.4
Description The Authentik project is vulnerable to Stored XSS attacks through the upload of crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user.
Recommendations For versions prior to 2024.10.4, update to version 2024.10.4 or later to protect against this risk. As a temporary workaround, consider restricting the upload of SVG files or disabling the feature to upload custom application icons until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2024-11623
CVE-2024-11623

Affected Products

Authentik