Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/apache/incubator-answer
  4. ›
  5. CVE-2026-25688

CVE-2026-25688: Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

June 9, 2026 (updated July 30, 2026)

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

References

  • github.com/advisories/GHSA-hmr2-99jm-8x45
  • lists.apache.org/thread/x42joj43rqb38ms5q60f7bgq3qbo7t5q
  • nvd.nist.gov/vuln/detail/CVE-2026-25688

Code Behaviors & Features

Detect and mitigate CVE-2026-25688 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.7.2-0.20260525024654-2746bf5b455f

Fixed versions

  • 1.7.2-0.20260525024654-2746bf5b455f

Solution

Upgrade to version 1.7.2-0.20260525024654-2746bf5b455f or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-87: Improper Neutralization of Alternate XSS Syntax

Source file

go/github.com/apache/incubator-answer/CVE-2026-25688.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 01 Aug 2026 00:17:08 +0000.