CVE-2026-82838

medium

Description

The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.

References

https://github.com/venueless/venueless/security/advisories/GHSA-38wh-hqvm-xgfc

Details

Source: Mitre, NVD

Published: 2026-08-31

Updated: 2026-09-03

CVSS v4

Base Score: 6.4

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H

Severity: Medium

EPSS

EPSS: 0.00234