Cross-site Scripting in Nacos
Moderate severity
GitHub Reviewed
Published
Mar 12, 2022
to the GitHub Advisory Database
•
Updated Jul 18, 2025
Package
Affected versions
>= 2.0.0-ALPHA.1, < 2.1.0-BETA
< 1.4.5
Patched versions
2.1.0-BETA
1.4.5
Description
Published by the National Vulnerability Database
Mar 11, 2022
Published to the GitHub Advisory Database
Mar 12, 2022
Reviewed
Mar 14, 2022
Last updated
Jul 18, 2025
A Cross Site Scripting (XSS) vulnerability exists in Nacos prior to 1.4.5 and 2.1.0-BETA in auth/users via the (1) pageSize and (2) pageNo parameters.
References