CVE-2025-64744: OpenObserve Vulnerable to HTML Injection in Organization Invitation Emails
OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML in the name, the markup is rendered inside the invitation email. This indicates that user-controlled input is inserted into the email template without proper HTML escaping. As of time of publication, no patched versions are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64744?
CVE-2025-64744 has a medium severity rating due to the potential for misuse of HTML markup in user invitations.
How do I fix CVE-2025-64744?
To fix CVE-2025-64744, upgrade OpenObserve to version 0.16.2 or higher.
What impact does CVE-2025-64744 have on user data?
CVE-2025-64744 can lead to email spoofing and potential phishing attacks due to unvalidated HTML in organization names.
Which versions of OpenObserve are affected by CVE-2025-64744?
CVE-2025-64744 affects all OpenObserve versions up to and including 0.16.1.
Is user input sanitized in OpenObserve for CVE-2025-64744?
No, user input is not properly sanitized in OpenObserve versions affected by CVE-2025-64744, leading to security risks.