Pinecone · Pinecone · CVE-2025-27155
**Name of the Vulnerable Software and Affected Versions**
Pinecone versions up to commit ea4c337
**Description**
The issue concerns stored cross-site scripting in the Pinecone Simulator (pineconesim). The payload storage is temporary and will be deleted when pineconesim is restarted.
**Recommendations**
For versions up to commit ea4c337, consider disabling the Pinecone Simulator until a fix is available to prevent potential exploitation.