PT-2025-49173 · Unknown · Monkeytype

Leonabcd123

·

Published

2025-12-04

·

Updated

2025-12-05

·

CVE-2025-66563

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Monkeytype versions prior to 25.49.0
Description The software exhibits improper handling of user input, potentially allowing an attacker to execute malicious JavaScript code on users who view a malicious quote submission. The quote.text and quote.source inputs are directly inserted into the Document Object Model (DOM) without sufficient sanitization. This allows HTML tags within these inputs to be rendered, potentially leading to cross-site scripting (XSS).
Recommendations Versions prior to 25.49.0 should be updated.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66563
GHSA-MFJH-9552-8G27

Affected Products

Monkeytype