CVE-2025-46655

Published Apr 26, 2025

Last updated 2 months ago

Overview

Description
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers.
Source
cve@mitre.org
NVD status
Awaiting Analysis
CNA Tags
disputed

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.9
Impact score
2.7
Exploitability score
1.8
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

cve@mitre.org
CWE-424

Social media

Hype score
Not currently trending