CVE-2025-27155

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-27155
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27155.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27155
Aliases
Related
Published
2025-03-04T17:15:18Z
Modified
2025-03-10T21:27:01.273014Z
Downstream
Summary
[none]
Details

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.

References

Affected packages

Git / github.com/matrix-org/pinecone

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/pinecone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.10.0
v0.11.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0