| id: GO-2025-3636 |
| modules: |
| - module: github.com/songquanpeng/one-api |
| unsupported_versions: |
| - last_affected: 0.6.10 |
| vulnerable_at: 0.6.10 |
| summary: one-api Cross-site Scripting vulnerability in github.com/songquanpeng/one-api |
| cves: |
| - CVE-2025-3801 |
| ghsas: |
| - GHSA-wvcx-j62q-45qw |
| references: |
| - advisory: https://github.com/advisories/GHSA-wvcx-j62q-45qw |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-3801 |
| - web: https://github.com/yaowenxiao721/Poc/blob/main/One-API/One-API-poc.md |
| - web: https://vuldb.com/?ctiid.305655 |
| - web: https://vuldb.com/?id.305655 |
| - web: https://vuldb.com/?submit.554702 |
| source: |
| id: GHSA-wvcx-j62q-45qw |
| created: 2025-04-22T11:21:20.399509-04:00 |
| review_status: UNREVIEWED |