PT-2025-49173 · Unknown · Monkeytype
Leonabcd123
·
Published
2025-12-04
·
Updated
2025-12-05
·
CVE-2025-66563
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Monkeytype versions prior to 25.49.0
Description
The software exhibits improper handling of user input, potentially allowing an attacker to execute malicious JavaScript code on users who view a malicious quote submission. The
quote.text and quote.source inputs are directly inserted into the Document Object Model (DOM) without sufficient sanitization. This allows HTML tags within these inputs to be rendered, potentially leading to cross-site scripting (XSS).Recommendations
Versions prior to 25.49.0 should be updated.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Monkeytype