PT-2025-32269 · Unknown · Agora Foundation

Msfv3N0M

·

Published

2025-08-07

·

Updated

2025-08-08

·

CVE-2025-55135

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Agora Foundation Agora fall23-Alpha1 versions prior to 690ce56
Description The application permits file formats other than PNG, JPEG, and WEBP for profile pictures, including SVG. This allows for cross-site scripting (XSS) via a crafted profile picture, impacting the server/controller/userController.js component. The vulnerability originates from insufficient file type validation in server/routes/userRoutes.js.
Recommendations Update Agora Foundation Agora to version 690ce56 or later.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-55135

Affected Products

Agora Foundation