XSS Vulnerability in Harbor Open Source Trusted Cloud Native Registry
CVE-2025-32019

4.1MEDIUM

Key Information:

Vendor

Goharbor

Status
Vendor
CVE Published:
23 July 2025

What is CVE-2025-32019?

Harbor, the open-source cloud native registry platform, has a Cross-Site Scripting (XSS) vulnerability in its markdown field on the info tab page. This flaw allows attackers to inject malicious scripts, potentially compromising user sessions and data integrity. The vulnerability affects Harbor versions 2.11.2 and earlier, including release candidates 2.12.0-rc1 and 2.13.0-rc1. Users are advised to upgrade to versions 2.11.3 or 2.12.3 or later to mitigate the risk.

Affected Version(s)

harbor >= 2.12.0-rc1, < 2.12.4-rc1 < 2.12.0-rc1, 2.12.4-rc1

harbor >= 2.13.0-rc1, < 2.13.1-rc1 < 2.13.0-rc1, 2.13.1-rc1

harbor <= 2.4.0-rc1.1, < 2.11.3 < 2.4.0-rc1.1, 2.11.3

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32019 : XSS Vulnerability in Harbor Open Source Trusted Cloud Native Registry