Cross-site scripting in Apache Allura - CVE-2026-80190
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in SVN code repositories when rendering stored repository content. A remote user can store a specially crafted payload in an SVN repository to execute arbitrary script code in a victim's browser.
Git repositories are not known to be affected.