PT-2026-5988 · Podinfo · Podinfo

Published

2026-02-03

·

Updated

2026-02-11

·

CVE-2025-70849

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions podinfo versions through 6.9.0
Description An arbitrary file upload issue exists in podinfo through version 6.9.0. Unauthenticated attackers can upload arbitrary files by sending a crafted POST request to the /store endpoint. The application does not implement a restrictive Content-Security-Policy (CSP) or perform adequate Content-Type validation when rendering uploaded content, which can lead to Stored Cross-Site Scripting (XSS). A Content-Security-Policy (CSP) is a security standard that helps prevent XSS attacks by controlling the resources the browser is allowed to load. Content-Type validation is the process of verifying that the type of data being uploaded matches the expected type.
Recommendations Update podinfo to a version newer than 6.9.0.

Exploit

Fix

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70849
GHSA-MW8W-Q3F7-2V85
GO-2026-4404
SUSE-SU-2026:0403-1

Affected Products

Podinfo