| id: GO-2026-4607 | |
| modules: | |
| - module: github.com/zitadel/zitadel | |
| non_go_versions: | |
| - introduced: 4.0.0 | |
| - fixed: 4.12.0 | |
| vulnerable_at: 1.87.5 | |
| summary: ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint in github.com/zitadel/zitadel | |
| cves: | |
| - CVE-2026-29191 | |
| ghsas: | |
| - GHSA-pr34-2v5x-6qjq | |
| references: | |
| - advisory: https://github.com/zitadel/zitadel/security/advisories/GHSA-pr34-2v5x-6qjq | |
| source: | |
| id: GHSA-pr34-2v5x-6qjq | |
| created: 2026-03-06T23:10:42.331059-05:00 | |
| review_status: UNREVIEWED |