PT-2026-3106 · Unknown · Sparkyfitness

Published

2026-01-15

·

Updated

2026-01-17

·

CVE-2025-65368

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SparkyFitness version 0.15.8.2
Description SparkyFitness is susceptible to Cross-Site Scripting (XSS) attacks. The issue stems from improper handling of user input and output from Large Language Models (LLMs). This allows for the injection of malicious scripts into web pages viewed by other users.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider sanitizing all user input and LLM output before rendering it in web pages.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-65368
GHSA-J7X6-6678-2XQP

Affected Products

Sparkyfitness