PT-2026-21020 · Unknown · @Sync-In/Server

Published

2026-02-20

·

Updated

2026-02-23

·

CVE-2025-67438

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sync-in Server versions prior to 1.9.3
Description A Stored Cross-Site Scripting (XSS) issue exists in Sync-in Server. An authenticated attacker can execute arbitrary JavaScript in a victim’s browser. This is achieved by uploading a crafted SVG file containing a malicious payload, potentially allowing the attacker to access and exfiltrate sensitive information, including the user's session cookies.
Recommendations Update Sync-in Server to version 1.9.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67438
GHSA-9JMQ-XGJM-P8C2

Affected Products

@Sync-In/Server