StackRadar

CVE-2026-5160

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
60
deployed by those charts
Fix available
1 of 1
affected package

Cross-site Scripting (XSS) in github.com/yuin/goldmark

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 60 images.

Affected packageAffected versionsFixed inImages
github.com/yuin/goldmarkgolangv1.1.25, v1.2.1, v1.3.5, v1.3.7+19 more1.7.1760
OSV records
GO-2026-5320
Also known as
GHSA-c97m-vxhj-p7j6

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
github.com/yuin/goldmark@v1.7.8
1.7.17
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
github.com/yuin/goldmark@v1.7.8
1.7.17

Open the chart page →

20,204
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
github.com/yuin/goldmark@v1.3.8
1.7.17

Open the chart page →

4,026
listmonklbenicio-communityVerified publisher0.1.01 of 1See more

listmonk lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
listmonk/listmonk:latestf535d59e1499
github.com/yuin/goldmark@v1.7.12
1.7.17

Open the chart page →

720
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.0.0bf3903d54a46
github.com/yuin/goldmark@v1.7.12
1.7.17

Open the chart page →

3,067
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/yuin/goldmark@v1.7.1
1.7.17

Open the chart page →

2,155
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/yuin/goldmark@v1.5.5
1.7.17

Open the chart page →

2,101
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
github.com/yuin/goldmark@v1.7.11
1.7.17

Open the chart page →

4,089
memosmt1905027.3.21 of 3See more

memos mt190502 7.3.2

1 of the 3 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
neosmemo/memos:0.26.23eefcc231141
github.com/yuin/goldmark@v1.7.13
1.7.17

Open the chart page →

2,443
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/yuin/goldmark@v1.7.4
1.7.17

Open the chart page →

2,968
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
github.com/yuin/goldmark@v1.5.6
1.7.17

Open the chart page →

3,430
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
github.com/yuin/goldmark@v1.2.1
1.7.17

Open the chart page →

4,861
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
github.com/yuin/goldmark@v1.7.11
1.7.17

Open the chart page →

4,089
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
github.com/yuin/goldmark@v1.5.4
1.7.17

Open the chart page →

1,872
vikunjapascaliskeVerified publisher5.1.01 of 1See more

vikunja pascaliske 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/yuin/goldmark@v1.7.4
1.7.17

Open the chart page →

1,342
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/yuin/goldmark@v1.7.13
1.7.17

Open the chart page →

1,837
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
github.com/yuin/goldmark@v1.4.0
1.7.17

Open the chart page →

2,960
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/yuin/goldmark@v1.7.4
1.7.17

Open the chart page →

4,070
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
github.com/yuin/goldmark@v1.7.8
1.7.17

Open the chart page →

1,674
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/yuin/goldmark@v1.5.4
1.7.17

Open the chart page →

2,015
tyk-dev-portaltyk-helm5.3.01 of 2See more

tyk-dev-portal tyk-helm 5.3.0

1 of the 2 container images this version deploys carry CVE-2026-5160.

Container imageDigestPackageFixed in
tykio/portal:v1.18.092509e00e618
github.com/yuin/goldmark@v1.7.4
1.7.17

Open the chart page →

867

Container images carrying it

60 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
github.com/yuin/goldmark@v1.7.8
1.7.17
1
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
github.com/yuin/goldmark@v1.7.8
1.7.17
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/yuin/goldmark@v1.7.1
1.7.17
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/yuin/goldmark@v1.5.5
1.7.17
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/yuin/goldmark@v1.5.4
1.7.17
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
github.com/yuin/goldmark@v1.4.8
1.7.17
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/yuin/goldmark@v1.7.13
1.7.17
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/yuin/goldmark@v1.5.5
1.7.17
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/yuin/goldmark@v1.7.13
1.7.17
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
github.com/yuin/goldmark@v1.7.13
1.7.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.