https://seclists.org/oss-sec/2025/q1/236: Mercurial 6.9.4 fixes CVE-2025-2361: XSS in hgweb
Published Mar 21, 2025
·Updated
Affected Software
1 affected component
Mercurial Mercurial
Frequently Asked Questions
1
What is the severity of CVE-2025-2361?
CVE-2025-2361 has been classified as a cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-2361?
To fix CVE-2025-2361, update Mercurial to version 6.9.4 or later.
3
What does CVE-2025-2361 affect?
CVE-2025-2361 affects the hgweb component of Mercurial.
4
When was CVE-2025-2361 published?
CVE-2025-2361 was published on March 21, 2025.
5
What is the risk of not addressing CVE-2025-2361?
Failing to address CVE-2025-2361 can lead to unauthorized script execution in user browsers.