CVE-2025-49126

Source
https://cve.org/CVERecord?id=CVE-2025-49126
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49126.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-49126
Aliases
  • GHSA-w36r-9jvx-q48v
Published
2025-06-23T17:18:51.857Z
Modified
2026-04-02T12:51:22.740339Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L CVSS Calculator
Summary
Visionatrix Vulnerable to Reflected XSS Leading to Exfiltration of Secrets
Details

Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the getswaggerui_html function from FastAPI. This function does not encode or sanitize its arguments before using them to generate the HTML for the swagger documentation page and is not intended to be used with user-controlled arguments. Any user of this application can be targeted with a one-click attack that can takeover their session and all the secrets that may be contained within it. This issue has been patched in version 2.5.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49126.json",
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/visionatrix/visionatrix

Affected ranges

Type
GIT
Repo
https://github.com/visionatrix/visionatrix
Events

Affected versions

v1.*
v1.10.0
v1.11.0
v1.11.1
v1.5.0
v1.6.0
v1.7.0
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.0.1.dev0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.4.1
v2.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49126.json"