ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
History

Fri, 17 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 18:45:00 +0000

Type Values Removed Values Added
Description ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
Title ThingsBoard < v4.2.1 SVG Image Stored XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-17T18:59:51.297Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34281

cve-icon Vulnrichment

Updated: 2025-10-17T18:59:48.159Z

cve-icon NVD

Status : Received

Published: 2025-10-17T19:15:37.197

Modified: 2025-10-17T19:15:37.197

Link: CVE-2025-34281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.