CVE-2025-65027
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious SVG or HTML files. When these files are accessed the browser executes embedded JavaScript, leading to stored Cross-Site Scripting (XSS) which when combined with a CSRF misconfiguration they lead to achieve full administrative account takeover, creating a rogue admin account, escalating the attacker account role to admin, and much more. This vulnerability is fixed in 4.4.1 and 4.4.1-beta.2.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
- Puntuación base: 7.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1189Drive-by Compromiseinitial access95 % - Impacto principal
T1059.007JavaScriptexecution90 % - Impacto secundario
T1098.002Additional Email Delegate Permissionspersistence · privilege escalation80 % - Impacto secundario
T1548.002Bypass User Account Controlprivilege escalation85 %
XSS almacenado via SVG/HTML con JS embebido (CWE-79) tras carga sin restricciones (CWE-434). Toma de control administrativo y escalada de privilegios confirmadas explícitamente.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-79, CWE-352, CWE-434
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-65027",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-65027",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-03T21:42:56.659839Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 5.5,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "rommapp",
"product": "romm",
"versions": [
{
"status": "affected",
"version": "< 4.4.1-beta.2"
}
]
}
]
}
],
"published": "2025-12-03T20:16:25.913",
"references": [
{
"url": "https://github.com/rommapp/romm/security/advisories/GHSA-v3c6-w996-f7hx",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
},
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious SVG or HTML files. When these files are accessed the browser executes embedded JavaScript, leading to stored Cross-Site Scripting (XSS) which when combined with a CSRF misconfiguration they lead to achieve full administrative account takeover, creating a rogue admin account, escalating the attacker account role to admin, and much more. This vulnerability is fixed in 4.4.1 and 4.4.1-beta.2."
},
{
"lang": "es",
"value": "RomM (ROM Manager) permite a los usuarios escanear, enriquecer, navegar y jugar sus colecciones de juegos con una interfaz limpia y responsiva. RomM contiene múltiples vulnerabilidades de carga de archivos sin restricciones que permiten a los usuarios autenticados subir archivos SVG o HTML maliciosos. Cuando se accede a estos archivos, el navegador ejecuta JavaScript incrustado, lo que lleva a Cross-Site Scripting (XSS) almacenado que, cuando se combina con una mala configuración de CSRF, conduce a lograr la toma de control total de la cuenta administrativa, creando una cuenta de administrador maliciosa, escalando el rol de la cuenta del atacante a administrador, y mucho más. Esta vulnerabilidad está corregida en 4.4.1 y 4.4.1-beta.2."
}
],
"lastModified": "2026-09-25T23:10:00.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:romm.app:romm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3501BC54-F9F3-4C68-AD5E-142908B2948C",
"versionEndExcluding": "4.4.1"
},
{
"criteria": "cpe:2.3:a:romm.app:romm:4.4.1:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93D1318D-39AA-4BCF-BACF-A869B8444BAE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}