CVE-2025-11147: Reflected Cross-site scripting (XSS) vulnerability in Apt-Cacher-NG
Published Sep 29, 2025
·Updated
Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”.
Affected Software
2 affected components
Apt-Cacher-NG Apt-Cacher-NG
Apt-cacher-ng Project Apt-cacher-ng=3.2-1
Remediation
Information
The vulnerability has been fixed by the Apt-Cacher-NG team in the latest available version.
Event History
Sep 29, 2025
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11147?
CVE-2025-11147 has a high severity rating due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2025-11147?
To fix CVE-2025-11147, upgrade Apt-Cacher-NG to version 3.2.2 or later, where this vulnerability has been addressed.
3
What kind of attack does CVE-2025-11147 enable?
CVE-2025-11147 enables reflected cross-site scripting (XSS) attacks that can execute malicious scripts in a user's browser.
4
Where in Apt-Cacher-NG is CVE-2025-11147 found?
CVE-2025-11147 is found in the handling of HTML files, specifically in the path '/html/<filename>.html'.
5
Who is affected by CVE-2025-11147?
Anyone using Apt-Cacher-NG version 3.2.1 is affected by CVE-2025-11147 and should take action to mitigate the risk.