MultiPortal has published security advisory MPSA-2026-001, a stored cross-site scripting issue in user and resource name fields.
Severity: High (CVSS v3.1 base 8.7)
Affected: MultiPortal Core 1.1.2, 1.1.3, and 1.2.0
Fixed in: 1.2.1
If you run an affected version, upgrade to 1.2.1 at your next maintenance window. The fix needs no data cleanup: existing names are made safe when they are displayed.
Read the full advisory, including impact, remediation, and workaround:
MPSA-2026-001 on docs.multiportal.io
The fix ships in the 1.2.1 release. To report a vulnerability privately, see Reporting security issues.