GSSA-2026-04-XJKMV4GITLAB-GSSA-2026-04-XJKMV4April 25, 20266.1 Medium
Permissive file upload filter accepts SVG enabling stored XSS in cobc-events
The multer fileFilter in cobc-events <1.0.1 used the regex `^(image|video|application/pdf)`, which matches `image/svg+xml` and any `video/*` MIME type. SVG uploads enable stored XSS when later served from the application origin.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Serve uploaded files from a separate, sandboxed origin (e.g. `usercontent.example.com`) until upgrade.
- Restrict the `submit_event` permission until upgrade.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
- Audit existing uploaded files for SVG payloads and remove any found.
Exploits
- Authenticated host uploads an SVG containing `<script>alert(document.cookie)</script>` as event proof; when a reviewer opens the proof URL, the script runs in the application's origin.
Overview
The multer fileFilter in cobc-events <1.0.1 used the regex ^(image|video|application/pdf), which matches image/svg+xml and any video/* MIME type. SVG uploads enable stored XSS when later served from the application origin.
Severity
CVSS v3
6.1 Medium
6.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
Weaknesses (3)
References (2)
- Patch in src/routes/views.js (Patch)
- OWASP: XSS (Technical description)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Stored cross-site scripting via uploaded SVG
CAPEC-592Session token theft via JS access to non-HttpOnly cookies
CAPEC-31
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published