PT-2025-9685 · Pinecone · Pinecone
Treanglex
·
Published
2025-03-04
·
Updated
2025-03-13
·
CVE-2025-27155
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pinecone versions up to commit ea4c337
Description
The issue concerns stored cross-site scripting in the Pinecone Simulator (pineconesim). The payload storage is temporary and will be deleted when pineconesim is restarted.
Recommendations
For versions up to commit ea4c337, consider disabling the Pinecone Simulator until a fix is available to prevent potential exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pinecone