blob: 29f63b4fe0e8aa9b818e1ff131ff2a957844d520 [file]
id: GO-2026-4607
modules:
- module: github.com/zitadel/zitadel
non_go_versions:
- introduced: 4.0.0
- fixed: 4.12.0
vulnerable_at: 1.87.5
summary: ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint in github.com/zitadel/zitadel
cves:
- CVE-2026-29191
ghsas:
- GHSA-pr34-2v5x-6qjq
references:
- advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-pr34-2v5x-6qjq
source:
id: GHSA-pr34-2v5x-6qjq
created: 2026-03-06T23:10:42.331059-05:00
review_status: UNREVIEWED