PT-2025-42641 · Unknown · Thingsboard

João Oliveira

+1

·

Published

2025-10-17

·

Updated

2026-02-10

·

CVE-2025-34281

CVSS v4.0

6.2

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions ThingsBoard versions prior to 4.2.1
Description The software contains a stored cross-site scripting (XSS) issue within the dashboard's Image Upload Gallery feature. An attacker can upload a Scalable Vector Graphics (SVG) file containing malicious JavaScript. This JavaScript may be executed when the file is rendered in the user interface. The issue is due to inadequate sanitization and improper content-type validation of uploaded SVG files.
Recommendations Update to version 4.2.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-34281
GHSA-FPQ4-R87V-G246

Affected Products

Thingsboard