Gokapi Stored Cross-Site Scripting Vulnerability via SVG Hotlinking

Vulnerability

A stored cross-site scripting vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. This issue allows malicious authenticated users to upload SVG files, create hotlinks for them, and execute arbitrary JavaScript. The vulnerability arises because the hotlinking feature does not properly sanitize scripts embedded in the SVGs, enabling authenticated attackers to execute JavaScript in the context of the user.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary JavaScript, potentially leading to various malicious actions such as stealing cookies or session tokens.

Remediation

Users are advised to update to Gokapi version 2.2.3 or later, where this vulnerability has been patched.

Added: Mar 6, 2026, 5:21 AM
Updated: Mar 6, 2026, 5:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
4.8
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.