PT-2025-30606 · Harbor · Harbor

Published

2025-07-23

·

Updated

2025-08-04

·

CVE-2025-32019

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harbor versions 2.11.2 and below Harbor versions 2.12.0-rc1 Harbor versions 2.13.0-rc1
Description Harbor, an open source trusted cloud native registry project, is susceptible to a stored cross-site scripting (XSS) issue. The markdown field within the info tab page can be exploited to inject malicious code.
Recommendations Update to Harbor version 2.11.3 or later. Update to Harbor version 2.12.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2025-32019
CVE-2025-32019
GHSA-F9VC-VF3R-PQQQ
GO-2025-3825
OPENSUSE-SU-2025:15405-1

Affected Products

Harbor