CVE-2025-13488: Nexus Repository 3 - Stored Cross-Site Scripting (XSS)
Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13488?
CVE-2025-13488 is classified as a moderate severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-13488?
To fix CVE-2025-13488, upgrade to a version of Sonatype Nexus Repository later than 3.83.0.
Who is affected by CVE-2025-13488?
CVE-2025-13488 affects users of Sonatype Nexus Repository version 3.83.0 with repository upload privileges.
What is the impact of CVE-2025-13488?
The impact of CVE-2025-13488 includes the potential for an attacker to execute malicious scripts in the context of authorized users.
What should I do if I cannot update to a fixed version for CVE-2025-13488?
If you cannot update to a fixed version for CVE-2025-13488, consider restricting user upload privileges until a patch is available.