Логотип exploitDog
bind:CVE-2025-53528
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-53528

Количество 2

Количество 2

nvd логотип

CVE-2025-53528

7 месяцев назад

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.3.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2gxp-6r36-m97r

7 месяцев назад

Cadwyn vulnerable to XSS on the docs page

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-53528

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.3.

CVSS3: 7.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-2gxp-6r36-m97r

Cadwyn vulnerable to XSS on the docs page

CVSS3: 7.6
0%
Низкий
7 месяцев назад

Уязвимостей на страницу