CVE-2025-42620
Last modified
CVE-2025-42620 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, which could lead to stored Cross-Site Scripting (XSS). On the backend, the related_vulnerabilities field of bundles accepted arbitrary strings without format validation or proper sanitization. On the frontend, comment and bundle descriptions were converted from Markdown to HTML and then injected directly into the DOM using string templates and innerHTML. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, which could lead to stored Cross-Site Scripting (XSS). On the backend, the related_vulnerabilities field of bundles accepted arbitrary strings without format validation or proper sanitization. On the frontend, comment and bundle descriptions were converted from Markdown to HTML and then injected directly into the DOM using string templates and innerHTML. This combination allowed an attacker who could create or edit comments or bundles to store crafted HTML/JavaScript payloads which would later be rendered and executed in the browser of any user visiting the affected profile page (user.html). This issue affects Vulnerability-Lookup: before 2.18.0.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-42620?
How severe is CVE-2025-42620?
How do I fix CVE-2025-42620?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-42605This vulnerability exists in Meon Bidding Solutions due to i…9.3
- CVE-2025-4261A vulnerability was found in GAIR-NLP factool up to 3f3914bc…5.3
- CVE-2025-42611RouterOS provides various services that rely on correct veri…6.5
- CVE-2025-42615In affected versions, vulnerability-lookup did not track or …8.1
- CVE-2025-42616Some endpoints in vulnerability-lookup that modified applic…7
- CVE-2025-4262A vulnerability was found in PHPGurukul Online DJ Booking Ma…9.8
- CVE-2025-4263A vulnerability was found in PHPGurukul Online DJ Booking Ma…9.8
- CVE-2025-4264A vulnerability classified as critical has been found in PHP…9.8
- CVE-2025-4265A vulnerability classified as critical was found in PHPGuruk…9.8
- CVE-2025-4266A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-4267A vulnerability, which was classified as critical, was found…7.2
- CVE-2025-4268A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374…6.9
Are you affected by CVE-2025-42620?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
