PT-2026-5133 · Amidaware · Tactical Rmm

Published

2026-01-28

·

Updated

2026-01-30

·

CVE-2025-69517

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amidaware Inc Tactical RMM versions 1.3.1 and earlier
Description An HTML injection issue in Tactical RMM allows authenticated users to inject arbitrary HTML content when creating a new agent via the /api/v3/newagent/ API endpoint. The agent id parameter, which accepts up to 255 characters, is not properly sanitized using DOMPurify.sanitize() with the html: true option, resulting in inadequate filtering of HTML input. This injected HTML is rendered within the Tactical RMM management panel when an administrator attempts to remove or shut down the affected agent, potentially enabling client-side attacks like UI manipulation or phishing. The DOMPurify.sanitize() function is used for sanitization.
Recommendations Versions prior to 1.3.1 should be updated.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-69517

Affected Products

Tactical Rmm