{"id":"CVE-2025-53865","aliases":["PYSEC-2025-69"],"url":"https://o3.security/vulnerability/CVE-2025-53865","summary":"Roundup is vulnerable to XSS through interactions between URLs and issue tracker templates","details":"In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).","published":"2025-07-13T21:30:31Z","modified":"2025-07-14T21:12:05.389708Z","cvss":{"score":6.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"roundup","fixedVersion":"2.5.0"}],"fix":{"url":"https://github.com/roundup-tracker/roundup/commit/3b1f22f331d4798491bd4746dbaaa6cfbe972952","label":"roundup-tracker/roundup@3b1f22f"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53865"},{"type":"WEB","url":"https://github.com/roundup-tracker/roundup/commit/3b1f22f331d4798491bd4746dbaaa6cfbe972952"},{"type":"WEB","url":"https://github.com/roundup-tracker/roundup/commit/65ac8f4dcb03a9a36a67c3e98fdf79cbd2a0b3fb"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2025-69.yaml"},{"type":"PACKAGE","url":"https://github.com/roundup-tracker/roundup"},{"type":"WEB","url":"https://www.roundup-tracker.org/docs/security.html"},{"type":"WEB","url":"https://www.roundup-tracker.org/docs/upgrading.html#cve-2025-53865"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-07-14T21:12:05.389708Z"}}