CVE-2025-53528

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.3.
Configurations

No configuration.

History

23 Jul 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

23 Jul 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : unknown
Summary (en) Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions 5.4.3 and below, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.4. (en) Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.3.

22 Jul 2025, 13:05

Type Values Removed Values Added
Summary
  • (es) Cadwyn crea un control de versiones de API moderno, similar a Stripe, basado en la comunidad y listo para producción en FastAPI. En las versiones 5.4.3 y anteriores, el parámetro de versión del endpoint "/docs" es vulnerable a un ataque XSS reflejado (Cross-Site Scripting). Este XSS permitiría a un atacante ejecutar código JavaScript en la sesión de un usuario para cualquier aplicación basada en Cadwyn mediante un ataque de un solo clic. La vulnerabilidad se ha corregido en la versión 5.4.4.

21 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 21:15

Updated : 2025-07-23 15:15


NVD link : CVE-2025-53528

Mitre link : CVE-2025-53528

CVE.ORG link : CVE-2025-53528


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')