Executive brief
ExpressGateway is an API gateway and middleware platform that routes HTTP requests. A cross-site scripting (XSS) vulnerability in its user management interface allows a logged-in user to unknowingly execute malicious JavaScript code in their browser, potentially stealing session data or credentials. The vulnerability requires an attacker to trick an authenticated user into viewing a specially crafted URL, making it a targeted attack with limited but real security impact.
Technical details
This is a reflected cross-site scripting (XSS / CWE-79) vulnerability in the REST endpoint at lib/rest/routes/users.js. User-supplied input in the HTTP request is reflected into the response without proper HTML escaping or sanitization, allowing arbitrary JavaScript injection. The attack is network-reachable but requires an authenticated user (low-privileged context) and user interaction—specifically, the victim must click a malicious link or visit a crafted URL. An attacker can achieve session hijacking, credential theft, or UI manipulation of the affected page. No patch information was disclosed in the advisory.
Affected products
- ExpressGateway express-gateway up to 1.16.10
Timeline
- 2025-08-18: disclosed
- 2025-08-19: advisory: GitHub security advisory published