{"schema_version":"1.9.0","id":"CVE-2025-32019","published":"2025-07-23T20:38:10.966Z","modified":"2026-08-12T03:51:47.567629396Z","aliases":["BIT-harbor-2025-32019","GHSA-f9vc-vf3r-pqqq","GO-2025-3825"],"related":["openSUSE-SU-2025:15405-1"],"summary":"Harbor's repository description page allows for XSS","details":"Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/goharbor/harbor","events":[{"introduced":"b3dab7a93cd8aa8921ee9f73652abc5b888f878b"},{"introduced":"15f3aabc0d548f9e87977338400fe6bdbcd240af"},{"fixed":"6b4981d4dd46a20481be5a3a7cdf435bc20f4dcb"},{"fixed":"9a932a0f9aadc93773a06c4d916f688254698cfa"},{"fixed":"76c2c5f7cfd9edb356cbb373889a59cc3217a058"},{"fixed":"a13a16383a41a8e20f524593cb290dc52f86f088"},{"fixed":"f019430872118852f83f96cac9c587b89052d1e5"}],"database_specific":{"extracted_events":[{"introduced":"2.12.0-rc1"},{"fixed":"2.12.4-rc1"},{"introduced":"2.13.0-rc1"},{"fixed":"2.13.1-rc1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.12.3-rc2","v2.12.3","v2.12.3-rc1","v2.13.0-rc2","v2.13.0","v2.13.0-rc1","v2.12.2-rc2","v2.12.2","v2.12.2-rc1","v2.12.1-rc3","v2.12.1","v2.12.1-rc2","v2.12.1-rc1","v2.12.0-rc2","v2.12.0","v2.12.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32019.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32019.json"},{"type":"ADVISORY","url":"https://github.com/goharbor/harbor/security/advisories/GHSA-f9vc-vf3r-pqqq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32019"},{"type":"FIX","url":"https://github.com/goharbor/harbor/commit/76c2c5f7cfd9edb356cbb373889a59cc3217a058"},{"type":"FIX","url":"https://github.com/goharbor/harbor/commit/a13a16383a41a8e20f524593cb290dc52f86f088"},{"type":"FIX","url":"https://github.com/goharbor/harbor/commit/f019430872118852f83f96cac9c587b89052d1e5"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32019.json","unresolved_ranges":[{"extracted_events":[{"introduced":"<= 2.4.0-rc1.1, < 2.11.3"},{"last_affected":"<= 2.4.0-rc1.1, < 2.11.3"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N"}]}