CVE-2025-55301
MEDIUMCVSS 6.7/10EPSS 0.16%
Last modified
CVE-2025-55301 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit the account's username locally. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit the account's username locally. This issue has been patched in version 1.1.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-55301?
The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit the account's username locally. This issue has been patched in version 1.1.
How severe is CVE-2025-55301?
CVE-2025-55301 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2025-55301?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-55296librenms is a community-based GPL-licensed network monitorin…5.4
- CVE-2025-55297ESF-IDF is the Espressif Internet of Things (IOT) Developmen…8.8
- CVE-2025-55298ImageMagick is free and open-source software used for editin…8.8
- CVE-2025-55299VaulTLS is a modern solution for managing mTLS (mutual TLS) …9.4
- CVE-2025-5530The WPC Smart Compare for WooCommerce plugin for WordPress i…5.4
- CVE-2025-55300Komari is a lightweight, self-hosted server monitoring tool …8.6
- CVE-2025-55303Astro is a web framework for content-driven websites. In ver…6.1
- CVE-2025-55304Exiv2 is a C++ library and a command-line utility to read, w…5.5
- CVE-2025-55305Electron is a framework for writing cross-platform desktop a…6.1
- CVE-2025-55306GenX_FX is an advance IA trading platform that will focus on…9.8
- CVE-2025-55307An issue was discovered in Foxit PDF and Editor for Windows …3.3
- CVE-2025-55308An issue was discovered in Foxit PDF and Editor for Windows …6.7
Are you affected by CVE-2025-55301?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
