CVE-2026-82838CWE-80
CVE-2026-82838
published August 31, 2026
What it is
The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.
The record
Technical detail
- CVSS
- 6.4 · NONE
- CVSS v4.0
- 6.4 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
- EPSS
- 0.00234 · 14.2th percentile
- Weakness
- CWE-80 · Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- Published
- 2026-08-31T12:17Z
References (1)
EPSS history
Timeline