ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Aug 18, 2025 
          to the GitHub Advisory Database
          •
          Updated Sep 23, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Aug 18, 2025 
    
  
        Published to the GitHub Advisory Database
      Aug 18, 2025 
    
  
        Reviewed
      Aug 19, 2025 
    
  
        Last updated
      Sep 23, 2025 
    
  
A cross-site scripting (XSS) issue exists in ExpressGateway ≤ 1.16.10 in lib/rest/routes/apps.js. User-controlled data returned by the REST endpoint is not sanitized before being rendered by the admin/UI layer, allowing an authenticated, low-privileged actor to store or reflect a payload that executes in a maintainer’s browser when the resource is viewed. The issue can be triggered remotely over the network and does not impact availability. No vendor fix is available at this time.
References