{"id":"GHSA-7xvh-c266-cfr5","summary":"@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome message","details":"### Description\n\nSince version 4.12.0, Dependency-Track users with the `SYSTEM_CONFIGURATION` permission can configure a \"welcome message\", which is HTML that is to be rendered on the login page for branding purposes.\n\nWhen rendering the welcome message, Dependency-Track versions before 4.13.6 did not properly sanitize the HTML, allowing arbitrary JavaScript to be executed.\n\n### Impact\n\nUsers with the `SYSTEM_CONFIGURATION` permission (i.e., administrators), can exploit this weakness to execute arbitrary JavaScript for users browsing to the login page. \n\n### Patches\n\nThe issue has been fixed in version 4.13.6.\n\n### References\n\n* The issue was introduced via: https://github.com/DependencyTrack/frontend/pull/986\n* The issue was fixed via: https://github.com/DependencyTrack/frontend/pull/1378\n\n### Credit\n\nThanks to *Jonas Benjamin Friedli* for identifying and responsibly disclosing the issue.","aliases":["CVE-2025-64758"],"modified":"2025-11-17T18:57:55Z","published":"2025-11-17T18:15:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-11-17T18:15:55Z","nvd_published_at":"2025-11-17T18:15:58Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/DependencyTrack/frontend/security/advisories/GHSA-7xvh-c266-cfr5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64758"},{"type":"WEB","url":"https://github.com/DependencyTrack/frontend/pull/1378"},{"type":"WEB","url":"https://github.com/DependencyTrack/frontend/pull/986"},{"type":"WEB","url":"https://github.com/DependencyTrack/frontend/commit/8fd757be612eaf4f35eadbe4c334204d7bd711be"},{"type":"PACKAGE","url":"https://github.com/DependencyTrack/frontend"}],"affected":[{"package":{"name":"@dependencytrack/frontend","ecosystem":"npm","purl":"pkg:npm/%40dependencytrack/frontend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.12.0"},{"fixed":"4.13.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7xvh-c266-cfr5/GHSA-7xvh-c266-cfr5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}