A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-1850 A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.
Fixes

Solution

The vulnerability has been resolved by EmbedAI team in version 2.1.


Workaround

No workaround given by the vendor.

History

Wed, 08 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Thesamur
Thesamur embedai
CPEs cpe:2.3:a:thesamur:embedai:*:*:*:*:*:*:*:*
Vendors & Products Thesamur
Thesamur embedai

Thu, 30 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 11:30:00 +0000

Type Values Removed Values Added
Description A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.
Title Reflected Cross-Site Scripting vulnerability in EmbedAI
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-02-18T19:02:02.663Z

Reserved: 2025-01-27T12:21:53.965Z

Link: CVE-2025-0746

cve-icon Vulnrichment

Updated: 2025-01-30T13:31:43.138Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T12:15:28.113

Modified: 2025-10-08T19:12:04.020

Link: CVE-2025-0746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.