CVE-2025-57665
Last modified
CVE-2025-57665 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. While native HTML anchor elements present similar risks, UI component libraries bear additional responsibility for implementing security safeguards and providing clear risk documentation. The vulnerability enables XSS attacks, phishing campaigns, and open redirect exploits affecting applications that use Element Plus Link components with user-controlled or untrusted URL inputs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Element-Plus | Element-Plus | <= 2.10.6 |
References
- https://github.com/element-plus/element-plus/pull/21711Exploit, Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-57665?
How severe is CVE-2025-57665?
How do I fix CVE-2025-57665?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-57639OS Command injection vulnerability in Tenda AC9 1.0 was disc…6.5
- CVE-2025-5764A vulnerability was found in code-projects Laundry System 1.…5.4
- CVE-2025-57642A Shell Upload vulnerability in Tourism Management System 2.…7.2
- CVE-2025-57644Accela Automation Platform 22.2.3.0.230103 contains multiple…9.1
- CVE-2025-5765A vulnerability was found in code-projects Laundry System 1.…5.4
- CVE-2025-5766A vulnerability was found in code-projects Laundry System 1.…4.3
- CVE-2025-5767The Crowdfunding for WooCommerce plugin for WordPress is vul…6.4
- CVE-2025-57681The WorklogPRO - Timesheets for Jira plugin in Jira Data Cen…5.4
- CVE-2025-57682Directory Traversal vulnerability in Papermark 0.20.0 and pr…6.5
- CVE-2025-57685The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-…8.8
- CVE-2025-57692PiranhaCMS 12.0 allows stored XSS in the Text content block …6.8
- CVE-2025-57697AstrBot Project v3.5.22 has an arbitrary file read vulnerabi…6.5
Are you affected by CVE-2025-57665?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
