CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
History

Mon, 23 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 22:30:00 +0000

Type Values Removed Values Added
Description CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Title CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
Weaknesses CWE-692
References
Metrics cvssV4_0

{'score': 2.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-18T22:14:06.323Z

Updated: 2025-06-23T16:41:36.205Z

Reserved: 2025-06-06T15:44:21.556Z

Link: CVE-2025-49590

cve-icon Vulnrichment

Updated: 2025-06-23T16:41:28.519Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-18T23:15:19.200

Modified: 2025-06-23T20:16:59.783

Link: CVE-2025-49590

cve-icon Redhat

No data.