CVE-2025-58353

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists such as r`eplace(/javascript:/gi, '')`. Because the package uses multi-character tokens and each replacement is applied only once, removing one occurrence can create a new dangerous token due to overlap. The “sanitized” value may still contain an executable payload when used in href/src (or injected into the DOM). There is currently no fix for this issue.
Configurations

No configuration.

History

04 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-04 20:15

Updated : 2025-09-05 17:47


NVD link : CVE-2025-58353

Mitre link : CVE-2025-58353

CVE.ORG link : CVE-2025-58353


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-184

Incomplete List of Disallowed Inputs