CVE-2026-28683 Details
Description
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a hotlink for it, they can achieve stored XSS. This issue has been patched in version 2.2.3.
A stored cross-site scripting vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. This issue allows malicious authenticated users to upload SVG files, create hotlinks for them, and execute arbitrary JavaScript. The vulnerability arises because the hotlinking feature does not properly sanitize scripts embedded in the SVGs, enabling authenticated attackers to execute JavaScript in the context of the user.
Users are advised to update to Gokapi version 2.2.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Forceu/Gokapi/releases/tag/v2.2.3 | [email protected] | Release Notes |
| https://github.com/Forceu/Gokapi/security/advisories/GHSA-3c22-5j5m-4jq7 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| forceu gokapi | < 2.2.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |