The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module.
There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:
* 1.13.3 or later
* 1.12.4 or later
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8727 | KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data. The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.3 or later * 1.12.4 or later |
| Link | Providers |
|---|---|
| https://www.knime.com/security/advisories#CVE-2025-3019 |
|
Wed, 08 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Knime
Knime business Hub |
|
| CPEs | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Knime
Knime business Hub |
|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data. The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.3 or later * 1.12.4 or later | |
| Title | Cross-site scripting vulnerabilities in KNIME Business Hub web pages | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: KNIME
Published:
Updated: 2025-03-31T12:45:32.162Z
Reserved: 2025-03-31T06:24:59.437Z
Link: CVE-2025-3019
Updated: 2025-03-31T12:45:00.232Z
Status : Analyzed
Published: 2025-03-31T07:15:19.133
Modified: 2025-10-08T17:18:01.070
Link: CVE-2025-3019
No data.
OpenCVE Enrichment
No data.
EUVD