Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-42620

Published Dec 8, 2025 CWE-79 EPSS 0.29% (22th pctl)

Overview

CVE-2025-42620 is a known-severity vulnerability. It was published on December 8, 2025.

Technical Description

In affected versions, vulnerability-lookup handled user-controlled

content in comments and bundles in an unsafe way, which could lead to

stored Cross-Site Scripting (XSS).

On the backend, the related_vulnerabilities field of bundles accepted

arbitrary strings without format validation or proper sanitization. On

the frontend, comment and bundle descriptions were converted from

Markdown to HTML and then injected directly into the DOM using string

templates and innerHTML. This combination allowed an attacker who could

create or edit comments or bundles to store crafted HTML/JavaScript

payloads which would later be rendered and executed in the browser of

any user visiting the affected profile page (user.html). 

This issue affects Vulnerability-Lookup: before 2.18.0.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2025-42620?

CVE-2025-42620 is a known-severity vulnerability. It was published on December 8, 2025.

How severe is CVE-2025-42620?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2025-42620?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-42620?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-42620 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.