{"schema_version":"1.7.3","id":"GHSA-v86x-5fm3-5p7j","published":"2023-08-23T20:42:43Z","modified":"2026-02-04T03:07:27.634811Z","aliases":["BIT-alertmanager-2023-40577","CVE-2023-40577","GO-2023-2020"],"related":["CGA-6v29-m49g-qxff"],"summary":"Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint","details":"### Impact\n\nAn attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager.\n\n### Patches\n\nUsers can upgrade to Alertmanager v0.2.51.\n\n### Workarounds\n\nUsers can setup a reverse proxy in front of the Alertmanager web server to forbid access to the /api/v1/alerts endpoint.\n\n### References\n\nN/A\n","affected":[{"package":{"name":"github.com/prometheus/alertmanager","ecosystem":"Go","purl":"pkg:golang/github.com/prometheus/alertmanager"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.25.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 0.25.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-v86x-5fm3-5p7j/GHSA-v86x-5fm3-5p7j.json"}}],"references":[{"type":"WEB","url":"https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40577"},{"type":"PACKAGE","url":"https://github.com/prometheus/alertmanager"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00011.html"}],"database_specific":{"cwe_ids":["CWE-79"],"github_reviewed":true,"github_reviewed_at":"2023-08-23T20:42:43Z","nvd_published_at":"2023-08-25T01:15:09Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}