CVE-2025-6596: Vector inserts portlet labels as HTML, allowing for stored XSS through system messages
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. This vulnerability is associated with program files resources/skins.Vector.Js/portlets.Js, resources/skins.Vector.Legacy.Js/portlets.Js.
This issue affects Vector: from >= 1.40.0 before 1.42.7, 1.43.2, 1.44.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6596?
The CVE-2025-6596 vulnerability has a moderate severity level due to the potential for stored XSS attacks.
How do I fix CVE-2025-6596?
To fix CVE-2025-6596, update Wikimedia Foundation Vector to a version newer than 1.42.7.
What impact does CVE-2025-6596 have on users?
CVE-2025-6596 allows attackers to execute malicious scripts in the context of a user's browser, potentially compromising user data.
What systems are affected by CVE-2025-6596?
CVE-2025-6596 affects Wikimedia Foundation Vector versions between 1.40.0 and 1.42.7.
Is CVE-2025-6596 a common vulnerability?
CVE-2025-6596 is a specific vulnerability found in the Vector skin for Wikimedia projects and is not widespread outside of this context.