Executive brief
Venueless is an open-source virtual event platform that allows users to upload content and attend online conferences. The default Docker image failed to properly restrict executable JavaScript in uploaded SVG files, allowing attackers to inject malicious scripts. A Content Security Policy has now been implemented to prevent this attack.
Technical details
The vulnerability is a cross-site scripting (XSS) issue stemming from inadequate Content Security Policy (CSP) configuration in the default Docker container. Uploaded SVG files could be delivered with executable JavaScript content, which would execute in users' browsers when viewing the files. This requires network access to the Venueless instance and low privileges (ability to upload SVG files). An attacker with upload access can inject malicious scripts that execute in the context of other users' sessions, potentially leading to session hijacking, data theft, or actions performed on behalf of the victim. The fix involves implementing a valid Content Security Policy to restrict script execution. The patch is available at commit 7dff888.
Affected products
- Venueless Venueless before commit 7dff888
Timeline
- 2026-08-31: disclosed: Advisory published on GitHub
- 2026-08-31: patched: Fix applied at commit 7dff888