You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate
davidegirardi
published
GHSA-fr62-mg2q-7wqvMar 4, 2025
Package
pinecone
Affected versions
<= ea4c33717fd74ef7d6f49490625a0fa10e3f5bbc
Patched versions
None
Description
Impact
The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconsim.
Patches
Commit TBA contains the fixes.
Workarounds
N/A
For more information
If you have any questions or comments about this advisory, please email us at security at matrix.org.
Impact
The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconsim.
Patches
Commit TBA contains the fixes.
Workarounds
N/A
For more information
If you have any questions or comments about this advisory, please email us at security at matrix.org.