GHSA-ph4x-8w6x-4q6x
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the QR code function in the manageapikeys component.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.