PT-2025-46906 · Unknown · Openobserve

Published

2025-11-13

·

Updated

2025-11-13

·

CVE-2025-64744

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenObserve versions prior to 0.16.2
Description OpenObserve is a cloud-native observability platform. When creating or renaming an organization with HTML in the name, the markup is rendered inside the invitation email. This occurs because user-controlled input is inserted into the email template without proper HTML escaping.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-64744
GHSA-3JPX-57GJ-W458

Affected Products

Openobserve