GHSA-fqc7-5xxc-ph7r
GitHub Security Advisory
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
Affected Packages
Maven
org.keycloak:keycloak-core
Affected versions:
0
(last affected: 16.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 1, 2025 6:44 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.