PT-2025-48541 · Doit · Todoist

Published

2025-12-01

·

Updated

2025-12-02

·

CVE-2025-63317

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Todoist version 8896
Description Todoist version 8896 has a Cross Site Scripting (XSS) issue in the /api/v1/uploads API endpoint. Uploaded SVG files lack sanitization, allowing embedded JavaScript to execute when a user opens the attachment from a task or comment. The vulnerable parameter is the SVG file itself.
Recommendations Apply sanitization to uploaded SVG files to prevent the execution of embedded JavaScript.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63317

Affected Products

Todoist