CVE-2025-11146: Reflected Cross-site scripting (XSS) vulnerability in Apt-Cacher-NG
Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11146?
CVE-2025-11146 is a medium severity vulnerability due to reflected cross-site scripting (XSS) risks.
How do I fix CVE-2025-11146?
To fix CVE-2025-11146, ensure that you properly sanitize and validate all GET inputs in the URL used in the Apt-Cacher-NG web management application.
Who is affected by CVE-2025-11146?
CVE-2025-11146 affects users of Apt-Cacher-NG version 3.2.1 and possibly earlier versions if they utilize the vulnerable feature.
What type of attack can be performed using CVE-2025-11146?
An attacker can perform reflected cross-site scripting (XSS) attacks exploiting CVE-2025-11146 to execute malicious scripts in unsuspecting users' browsers.
When was CVE-2025-11146 disclosed?
CVE-2025-11146 was disclosed on October 1, 2025.