CVE-2025-49590

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-49590
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49590.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-49590
Aliases
  • GHSA-vq9h-x3gr-v8rj
Published
2025-06-18T23:15:19Z
Modified
2025-06-26T21:05:05.235679Z
Summary
[none]
Details

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.

References

Affected packages

Git / github.com/cryptpad/cryptpad

Affected ranges

Type
GIT
Repo
https://github.com/cryptpad/cryptpad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.2.0
0.3.0

1.*

1.0.0
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.29.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0

2.*

2.0.0
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.05
2.17.06
2.18.0
2.19.0
2.2.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0

2024.*

2024.12.0
2024.3.0
2024.3.1
2024.6.0
2024.6.1
2024.9.0
2024.9.1

3.*

3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.12.0
3.13.0
3.14.0
3.15.0
3.16.0
3.17.0
3.17.1
3.18.0
3.18.1
3.19.0
3.19.1
3.2.0
3.20.0
3.20.1
3.21.0
3.22.0
3.23.0
3.23.1
3.23.2
3.24.0
3.25.0
3.25.1
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.9.0

4.*

4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.12.1
4.13.0
4.14.0
4.14.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0

5.*

5.0.0
5.1.0
5.2.0
5.2.1
5.3.0
5.4.0
5.4.1
5.5.0
5.6.0
5.7.0

Other

opendesk-20231020
opendesk-20231222
opendesk-20241022

v1.*

v1.14.0
v1.15.0