THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g8rh-fjm6-h2h9 (low) — LF Edge eKuiper: Self-XSS in External Service Creation

[GHSA] GHSA-g8rh-fjm6-h2h9 (low) — LF Edge eKuiper: Self-XSS in External Service Creation

medgithub_advisoriesPublished 2026-09-09

GHSA-g8rh-fjm6-h2h9 Severity: low CVE: CVE-2025-24978

LF Edge eKuiper: Self-XSS in External Service Creation

### Summary A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.

### Details Prior to v2.4

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g8rh-fjm6-h2h9