CVE-2025-61987
MEDIUMCVSS 6.9/10EPSS 0.14%
Last modified
CVE-2025-61987 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Groupsession | Groupsession | < 5.3.0 |
| Groupsession | Groupsession | < 5.3.2 |
| Groupsession | Groupsession | < 5.3.3 |
References
- https://groupsession.jp/info/info-news/security20251208Vendor Advisory
- https://jvn.jp/en/jp/JVN19940619/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-61987?
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
How severe is CVE-2025-61987?
CVE-2025-61987 has a CVSS score of 6.9/10 (MEDIUM severity). The EPSS model estimates a 0.14% probability of exploitation in the next 30 days.
How do I fix CVE-2025-61987?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-61979An out-of-bounds read vulnerability exists in the EMF functi…7.1
- CVE-2025-6198There is a vulnerability in the Supermicro BMC firmware vali…7.2
- CVE-2025-61982An arbitrary code execution vulnerability exists in the Code…7.8
- CVE-2025-61983Heap-based Buffer Overflow vulnerability in TP-Link Archer A…8
- CVE-2025-61984ssh in OpenSSH before 10.1 allows control characters in user…3.6
- CVE-2025-61985ssh in OpenSSH before 10.1 allows the '\0' character in an s…3.6
- CVE-2025-6199A flaw was found in the GIF parser of GdkPixbuf’s LZW decode…3.3
- CVE-2025-61990When using a multi-bladed platform with more than one blade,…8.7
- CVE-2025-61994Cross-site scripting vulnerability exists in GROWI prior to …5.4
- CVE-2025-61996OPEXUS FOIAXpress before 11.13.3.0 allows an administrative …4.8
- CVE-2025-61997OPEXUS FOIAXpress before 11.13.3.0 allows an administrative …4.8
- CVE-2025-61998OPEXUS FOIAXpress before 11.13.3.0 allows an administrative …4.8
Are you affected by CVE-2025-61987?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
