CVE-2025-65516

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/12/2025
Last modified:
11/12/2025

Description

A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an attacker can upload a crafted SVG file containing malicious JavaScript and share it using a public link. Opening the link triggers script execution in the victim's browser. This issue has been fixed in Seafile Community Edition 13.0.12.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:seafile:seafile_server:*:*:*:*:community:*:*:* 13.0.12 (excluding)