PT-2025-42521 · Mqttx · Mqttx

Published

2025-10-16

·

Updated

2025-10-17

·

CVE-2025-62413

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MQTTX version 1.12.0
Description MQTTX, an MQTT 5.0 desktop client and testing tool, contains a flaw where improperly handled MQTT message payloads can lead to Cross-Site Scripting (XSS). Malicious payloads with HTML or JavaScript could be rendered in the MQTTX message viewer, potentially allowing attackers to execute scripts within the application's user interface. This could lead to unauthorized access to MQTT connection credentials or the triggering of unintended actions. The issue is particularly relevant in untrusted or multi-tenant environments where message content is not fully controlled.
Recommendations Update to MQTTX version 1.12.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62413
GHSA-29GF-9R9V-J4M3

Affected Products

Mqttx