CVE-2025-4215
Last modified
CVE-2025-4215 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.63.3b17 is able to address this issue. The patch is identified as eaedaf5b10d2f7857c6b77fbf7d4a80681d4d46c. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ublockorigin | Ublock Origin | < 1.63.3 | — |
| Ublockorigin | Ublock Origin | 1.63.3 | Beta1 |
| Debian | Debian Linux | 11.0 | — |
References
- https://vuldb.com/?ctiid.307194Permissions Required, VDB Entry
- https://vuldb.com/?id.307194Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.562301Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4215?
How severe is CVE-2025-4215?
How do I fix CVE-2025-4215?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4209Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-4210A vulnerability classified as critical was found in Casdoor …7.3
- CVE-2025-4211Improper Link Resolution Before File Access ('Link Following…7.3
- CVE-2025-4212The Checkout Files Upload for WooCommerce plugin for WordPre…7.2
- CVE-2025-4213A vulnerability has been found in PHPGurukul Online Birth Ce…9.8
- CVE-2025-4214A vulnerability was found in PHPGuruku Online DJ Booking Man…9.8
- CVE-2025-4216The DIOT SCADA with MQTT plugin for WordPress is vulnerable …6.4
- CVE-2025-4217The WP YouTube Video Optimizer plugin for WordPress is vulne…6.4
- CVE-2025-4218A vulnerability was found in handrew browserpilot up to 0.2.…7.8
- CVE-2025-4219The DPEPress plugin for WordPress is vulnerable to Stored Cr…6.4
- CVE-2025-4220The Xavin's List Subpages plugin for WordPress is vulne…6.4
- CVE-2025-4221The Animated Buttons plugin for WordPress is vulnerable to S…6.4
Are you affected by CVE-2025-4215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
