CVE-2025-52842: Laundry 2.3.0 - Account Takeover via Reflected XSS
Published Jul 2, 2025
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on Linux, MacOS allows Account Takeover. This issue affects Laundry: 2.3.0.
Affected Software
4 affected components
Laundry Laundry
All of the following
Laundry Project Laundry=2.3.0
Any of the following
Apple macOS
Linux Linux kernel
Event History
Jul 2, 2025
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52842?
CVE-2025-52842 is considered a high severity vulnerability due to its potential for account takeover.
2
How do I fix CVE-2025-52842?
To fix CVE-2025-52842, update Laundry to version 2.3.1 or later, which addresses the vulnerability.
3
What kind of vulnerability is CVE-2025-52842?
CVE-2025-52842 is an XSS (Cross-site Scripting) vulnerability that involves improper neutralization of input during web page generation.
4
Which software is affected by CVE-2025-52842?
CVE-2025-52842 affects Laundry versions prior to 2.3.1 on both Linux and MacOS platforms.
5
Can CVE-2025-52842 lead to data breaches?
Yes, CVE-2025-52842 can lead to account takeover, which may result in data breaches if exploited.