CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18910 CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 11 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki cryptpad
CPEs cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:*
Vendors & Products Xwiki
Xwiki cryptpad
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 23 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 22:30:00 +0000

Type Values Removed Values Added
Description CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Title CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
Weaknesses CWE-692
References
Metrics cvssV4_0

{'score': 2.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-23T16:41:36.205Z

Reserved: 2025-06-06T15:44:21.556Z

Link: CVE-2025-49590

cve-icon Vulnrichment

Updated: 2025-06-23T16:41:28.519Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-18T23:15:19.200

Modified: 2025-08-11T18:18:19.470

Link: CVE-2025-49590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.