CVE-2026-82838
EUVD-2026-6839231.08.2026, 08:17
The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.
Awaiting analysis
This vulnerability is currently awaiting analysis.