Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26851 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` and a few patterns. `data:` URLs (for example data:image/svg+xml,…) still pass. If a sanitized value is used in href/src, an attacker can execute a script. There is currently no fix for this issue. |
Fri, 05 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Promptcraft-forge-studio Project
Promptcraft-forge-studio Project promptcraft-forge-studio |
|
| Vendors & Products |
Promptcraft-forge-studio Project
Promptcraft-forge-studio Project promptcraft-forge-studio |
Thu, 04 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` and a few patterns. `data:` URLs (for example data:image/svg+xml,…) still pass. If a sanitized value is used in href/src, an attacker can execute a script. There is currently no fix for this issue. | |
| Title | Promptcraft Forge Studio's incomplete URL check is vulnerable to XSS via SVG | |
| Weaknesses | CWE-184 CWE-20 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-04T20:07:02.787Z
Reserved: 2025-08-29T16:19:59.010Z
Link: CVE-2025-58361
Updated: 2025-09-04T20:06:57.668Z
Status : Deferred
Published: 2025-09-04T20:15:39.617
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-58361
No data.
OpenCVE Enrichment
Updated: 2025-09-05T14:02:26Z
EUVD