PT-2025-53434 · Postmanlabs · Httpbin

Zast.Ai

·

Published

2025-12-26

·

Updated

2025-12-26

·

CVE-2025-15095

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions postmanlabs httpbin versions up to 0.6.1
Description A security issue exists in postmanlabs httpbin up to version 0.6.1. The issue involves cross site scripting and affects an unknown function within the httpbin-master/httpbin/core.py file. The attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 0.6.1 should be used.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15095

Affected Products

Httpbin