fig. 01 — GO-2023-1471, the advisory selected below
// advisories
GO-2023-1471
UNKNOWN
Gotify exposes an outdated instance of the [Swagger UI](https://swagger.io/tools/swagger-ui/) API documentation frontend at /docs which is susceptible to reflected XSS attacks when loading external Swagger config files.