Cross-site scripting in gogs - CVE-2025-47943
Published: April 27, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary javascript code in the victim's browser.
The vulnerability exists due to cross-site scripting in the PDF renderer using pdfjs-1.4.20 when previewing an uploaded PDF file. A remote user can upload a specially crafted PDF file to execute arbitrary javascript code in the victim's browser.
User interaction is required to click on the uploaded file for preview.