{"id":"CVE-2025-32960","summary":"CUBA Generic REST API Vulnerable to Cross-Site Scripting (XSS) in the /files Endpoint","details":"The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the browser. For a successful attack, a malicious file needs to be uploaded beforehand. This issue has been patched in version 7.2.7. A workaround is provided on the Jmix documentation website.","aliases":["GHSA-88h5-34xw-2q56"],"modified":"2026-08-12T15:13:27.600288Z","published":"2025-04-22T17:45:53.855Z","related":["GHSA-88h5-34xw-2q56","GHSA-x27v-f838-jh93"],"database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32960.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://docs.jmix.io/jmix/files-vulnerabilities.html"},{"type":"WEB","url":"https://docs.jmix.io/jmix/files-vulnerabilities.html#disable-files-endpoint-in-cuba-application"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32960.json"},{"type":"ADVISORY","url":"https://github.com/cuba-platform/restapi/security/advisories/GHSA-88h5-34xw-2q56"},{"type":"ADVISORY","url":"https://github.com/jmix-framework/jmix/security/advisories/GHSA-x27v-f838-jh93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32960"},{"type":"FIX","url":"https://github.com/cuba-platform/restapi/commit/b3d599f6657d7e212fdb134a61ab5e0888669eb1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cuba-platform/restapi","events":[{"introduced":"0"},{"fixed":"b3d599f6657d7e212fdb134a61ab5e0888669eb1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.2.7"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v7.2.6","v7.2.5","v7.2.3","v7.2.2","v7.2.0","v7.2.0.BETA2","v7.2.0.BETA1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32960.json","vanir_signatures_modified":"2026-08-12T15:13:27Z","vanir_signatures":[{"id":"CVE-2025-32960-2a796838","signature_type":"Function","signature_version":"v1","source":"https://github.com/cuba-platform/restapi/commit/b3d599f6657d7e212fdb134a61ab5e0888669eb1","target":{"file":"modules/rest-api/src/com/haulmont/addon/restapi/api/controllers/FileDownloadController.java","function":"downloadFile"},"deprecated":false,"digest":{"function_hash":"54200476744645788036700556673148464282","length":1224}},{"digest":{"line_hashes":["67182121229851448952844801850171581628","254701135178457847314084078399411955844","301316498773120368418498872189720552775","292111146108943648242344266082789239429","43116381516680375384121855875653714972","225113231891697709946925762082043570377"],"threshold":0.9},"id":"CVE-2025-32960-677478c9","signature_type":"Line","signature_version":"v1","source":"https://github.com/cuba-platform/restapi/commit/b3d599f6657d7e212fdb134a61ab5e0888669eb1","target":{"file":"modules/global/src/com/haulmont/addon/restapi/api/config/RestApiConfig.java"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/cuba-platform/restapi/commit/b3d599f6657d7e212fdb134a61ab5e0888669eb1","target":{"file":"modules/rest-api/src/com/haulmont/addon/restapi/api/controllers/FileDownloadController.java"},"deprecated":false,"digest":{"line_hashes":["254300683170600550642917213360086627492","285892161726166325320276996057450211142","332857588120453033035124379745475889410","286549100876390447999995882015714377773","2265221444674032896482196102923561914","101003447775308206494314163185329705853","255243430482979581250663692374347555985","336034280416598264724881359193451257931","172182862985667924364984343603054943426","167697077608159051115525551100261317647","97700280060694950511671376452218888334","222623144284906587510761705433814341520","10960967703388405574078425875764088791","61355570620212318915422324477359043720","156956546100249099853681764417798671101","22095937723749975876907027910505307312","159058960925332754364072282101566188078"],"threshold":0.9},"id":"CVE-2025-32960-e7aed99b"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}