Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.
History

Thu, 24 Jul 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Goharbor
Goharbor harbor
Vendors & Products Goharbor
Goharbor harbor

Wed, 23 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
Description Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.
Title Harbor's repository description page allows for XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-23T20:38:10.966Z

Updated: 2025-07-23T20:47:47.745Z

Reserved: 2025-04-01T21:57:32.954Z

Link: CVE-2025-32019

cve-icon Vulnrichment

Updated: 2025-07-23T20:47:41.730Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-23T21:15:26.037

Modified: 2025-07-25T15:29:44.523

Link: CVE-2025-32019

cve-icon Redhat

No data.