PT-2025-44311 · Ckan · Ckan

Published

2025-10-29

·

Updated

2025-10-29

·

CVE-2025-54384

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions CKAN versions prior to 2.10.9 CKAN versions prior to 2.11.4
Description CKAN, an open-source data management system, contains a flaw in the helpers.markdown extract() function. Insufficient input sanitization before wrapping data in an HTML literal element can lead to a potential cross-site scripting (XSS) vector. This impacts the rendering of user-provided data on dataset, resource, organization, or group pages, as well as pages provided by extensions utilizing this helper function.
Recommendations Update to CKAN version 2.10.9 or later. Update to CKAN version 2.11.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54384
GHSA-2R4H-8JXV-W2J8

Affected Products

Ckan