one-apiGHSA-wvcx-j62q-45qw
one-api Cross-site Scripting vulnerability
Medium2.4CVE-2025-3801 · Published Apr 19, 2025 · updated Apr 22, 2025
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/songquanpeng/one-api Go | <= 0.6.10 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2025-3801, GO-2025-3636
More one-api advisories
All one-api| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 8 | songquanpeng one-api has an issue that results in business logic errors | Low3.1 | No fix yet |