In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate severity
GitHub Reviewed
Published
Mar 4, 2025
in
matrix-org/pinecone
•
Updated Mar 4, 2025
Package
Affected versions
<= 0.11.0
Patched versions
None
Description
Published by the National Vulnerability Database
Mar 4, 2025
Published to the GitHub Advisory Database
Mar 4, 2025
Reviewed
Mar 4, 2025
Last updated
Mar 4, 2025
Impact
The Pinecone Simulator (pineconesim) included in Pinecone up to commit matrix-org/pinecone@ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconsim.
Patches
Commit matrix-org/pinecone@218b280 contains the fixes.
Workarounds
N/A
For more information
If you have any questions or comments about this advisory, please email us at security at matrix.org.
References