Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
High
Attack Requirements
None
Privileges Required
High
User Interaction
Active
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
Affected products
- Octopus Deploy / Octopus Server2023.0.0 – 2025.4.10678
- Octopus Deploy / Octopus Server2026.1.0 – 2026.1.11451
- Octopus Deploy / Octopus Server2026.2.0 – 2026.2.13114
References
- VENDOR_ADVISORYhttps://advisories.octopus.com/post/2026/sa2026-05