{"id":"CVE-2018-25031","aliases":["GHSA-cr3q-pqgq-m8c2"],"url":"https://o3.security/vulnerability/CVE-2018-25031","summary":"Spoofing attack in swagger-ui","details":"Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.","published":"2022-03-11T07:15:07.190Z","modified":"2026-07-08T19:45:35.973437Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},"epss":{"score":0.42326,"percentile":0.98615,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.webjars:swagger-ui","fixedVersion":"4.1.3"},{"ecosystem":"npm","name":"swagger-ui","fixedVersion":"4.1.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/swagger-api/swagger-ui/releases/tag/v4.1.3"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220407-0004/"},{"type":"FIX","url":"https://github.com/swagger-api/swagger-ui/issues/4872"},{"type":"FIX","url":"https://security.snyk.io/vuln/SNYK-JS-SWAGGERUI-2314885"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:45:35.973437Z"}}