CVE-2025-49590

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
11/08/2025

Description

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:* 2025.3.0 (excluding)