CVE-2025-67634: Software Acquisition Guide Supplier Response Web Tool XSS
Published Dec 12, 2025
·Updated
The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').
Affected Software
2 affected components
CISA Software Acquisition Guide Supplier Response Web Tool<2025-12-11
CISA Software Acquisition Guide<2025-12-11
Event History
Dec 12, 2025
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 18, 58737
Event
via NVD·09:57 AM
Frequently Asked Questions
1
What should users of the CISA Software Acquisition Guide Supplier Response Web Tool be aware of regarding CVE-2025-67634?
Users should be cautious of importing JSON files from untrusted sources to avoid exploitation from CVE-2025-67634.