Showing 2 vulnerabilities on this page for com.palantir.acme.gaia:gaia

Signals CISA KEV Ransomware Nuclei
Palantir vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Gaia unauthenticated endpoints

Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.

CWE-287CWE-592Dec 19, 2025
CVSS6.8v3.1EPSS0.203%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stored XSS in gaia

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.

CWE-434Mar 12, 2024
CVSS6.8v3.1EPSS0.456%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX