« Volver al listado

CVE-2025-46655

Estado: AplazadaMedia (4.9)—

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-46655",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-46655",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-29T14:05:51.667886Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "HackMD",
          "product": "CodiMD",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "2.5.4"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-04-26T21:15:15.260",
  "references": [
    {
      "url": "https://github.com/hackmdio/codimd/issues/1910",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/zast-ai/vulnerability-reports/blob/main/formidable/file_upload/report.md",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/hackmdio/codimd/issues/1910",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-424"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers."
    },
    {
      "lang": "es",
      "value": "CodiMD hasta la versión 2.5.4 cuenta con un mecanismo de protección basado en CSP contra XSS mediante la carga de documentos SVG que contienen JavaScript, pero este mecanismo puede omitirse en ciertos casos de almacenamiento de archivos de origen diferente, como AWS S3. NOTA: Esto puede considerarse un error del usuario si se utiliza AWS para alojar contenido JavaScript no confiable, pero la arquitectura seleccionada dentro de AWS no cuenta con componentes que permitan insertar encabezados Content-Security-Policy."
    }
  ],
  "lastModified": "2026-06-17T09:26:46.997",
  "sourceIdentifier": "cve@mitre.org"
}