{"id":"CVE-2025-64758","aliases":["GHSA-7xvh-c266-cfr5"],"url":"https://o3.security/vulnerability/CVE-2025-64758","summary":"@dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message","details":"@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a \"welcome message\", which is HTML that is to be rendered on the login page for branding purposes. When rendering the welcome message, Dependency-Track versions before 4.13.6 did not properly sanitize the HTML, allowing arbitrary JavaScript to be executed. Users with the SYSTEM_CONFIGURATION permission (i.e., administrators), can exploit this weakness to execute arbitrary JavaScript for users browsing to the login page. The issue has been fixed in version 4.13.6.","published":"2025-11-17T17:24:27.491Z","modified":"2026-08-12T03:51:46.603395859Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@dependencytrack/frontend","fixedVersion":"4.13.6"}],"fix":{"url":"https://github.com/DependencyTrack/frontend/commit/8fd757be612eaf4f35eadbe4c334204d7bd711be","label":"DependencyTrack/frontend@8fd757b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64758.json"},{"type":"ADVISORY","url":"https://github.com/DependencyTrack/frontend/security/advisories/GHSA-7xvh-c266-cfr5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64758"},{"type":"FIX","url":"https://github.com/DependencyTrack/frontend/commit/8fd757be612eaf4f35eadbe4c334204d7bd711be"},{"type":"FIX","url":"https://github.com/DependencyTrack/frontend/pull/1378"},{"type":"FIX","url":"https://github.com/DependencyTrack/frontend/pull/986"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.603395859Z"}}