CVE-2025-64758
Last modified
CVE-2025-64758 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a "welcome message", which is HTML that is to be rendered on the login page for branding purposes. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a "welcome message", which is HTML that is to be rendered on the login page for branding purposes. When rendering the welcome message, Dependency-Track versions before 4.13.6 did not properly sanitize the HTML, allowing arbitrary JavaScript to be executed. Users with the SYSTEM_CONFIGURATION permission (i.e., administrators), can exploit this weakness to execute arbitrary JavaScript for users browsing to the login page. The issue has been fixed in version 4.13.6.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-64758?
How severe is CVE-2025-64758?
How do I fix CVE-2025-64758?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64752grist-core is a spreadsheet hosting server. Prior to version…6.5
- CVE-2025-64753grist-core is a spreadsheet hosting server. Prior to version…6.5
- CVE-2025-64754Jitsi Meet is an open source video conferencing application.…2.7
- CVE-2025-64755Claude Code is an agentic coding tool. Prior to version 2.0.…9.8
- CVE-2025-64756Glob matches files using patterns the shell uses. Starting i…7.5
- CVE-2025-64757Astro is a web framework. Prior to version 5.14.3, a vulnera…3.5
- CVE-2025-64759Homarr is an open-source dashboard. Prior to version 1.43.3,…6.1
- CVE-2025-6476A vulnerability was found in SourceCodester Gym Management S…4.3
- CVE-2025-64760Tuleap is a free and open source suite for management of sof…4.3
- CVE-2025-64761OpenBao is an open source identity-based secrets management …7.2
- CVE-2025-64762The AuthKit library for Next.js provides convenient helpers …9.1
- CVE-2025-64763Envoy is a high-performance edge/middle/service proxy. In 1.…5.3
Are you affected by CVE-2025-64758?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
