{"id":"GHSA-v86x-5fm3-5p7j","summary":"Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint","details":"### Impact\n\nAn attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager.\n\n### Patches\n\nUsers can upgrade to Alertmanager v0.2.51.\n\n### Workarounds\n\nUsers can setup a reverse proxy in front of the Alertmanager web server to forbid access to the /api/v1/alerts endpoint.\n\n### References\n\nN/A\n","aliases":["BIT-alertmanager-2023-40577","CVE-2023-40577","GO-2023-2020"],"modified":"2026-07-17T21:05:46.948836862Z","published":"2023-08-23T20:42:43Z","database_specific":{"github_reviewed_at":"2023-08-23T20:42:43Z","nvd_published_at":"2023-08-25T01:15:09Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/prometheus/alertmanager/security/advisories/GHSA-v86x-5fm3-5p7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40577"},{"type":"PACKAGE","url":"https://github.com/prometheus/alertmanager"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00011.html"}],"affected":[{"package":{"name":"github.com/prometheus/alertmanager","ecosystem":"Go","purl":"pkg:golang/github.com/prometheus/alertmanager"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.25.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-v86x-5fm3-5p7j/GHSA-v86x-5fm3-5p7j.json","last_known_affected_version_range":"\u003c= 0.25.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}