CVE-2025-67634
Last modified
CVE-2025-67634 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisa | Software Acquisition Guide | < 2025-12-11 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67634?
How severe is CVE-2025-67634?
How do I fix CVE-2025-67634?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67629Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-6763A vulnerability was found in Comet System T0510, T3510, T351…8.2
- CVE-2025-67630Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-67631Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-67632Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-67633Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-67635Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not …7.5
- CVE-2025-67636A missing permission check in Jenkins 2.540 and earlier, LTS…4.3
- CVE-2025-67637Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores bu…4.3
- CVE-2025-67638Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not …4.3
- CVE-2025-67639A cross-site request forgery (CSRF) vulnerability in Jenkins…3.5
- CVE-2025-67640Jenkins Git client Plugin 6.4.0 and earlier does not not cor…5
Are you affected by CVE-2025-67634?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
