icon

We found results for “

CVE-2025-49590

Good to know:

icon

Date: June 18, 2025

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.

Severity Score

Weakness Type (CWE)

Incomplete Denylist to Cross-Site Scripting

CWE-692

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/cryptpad/cryptpad.git - 2025.3.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us