ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Thingsboard
Thingsboard thingsboard |
|
Vendors & Products |
Thingsboard
Thingsboard thingsboard |
Fri, 17 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Oct 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files. | |
Title | ThingsBoard < v4.2.1 SVG Image Stored XSS | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-17T18:59:51.297Z
Reserved: 2025-04-15T19:15:22.581Z
Link: CVE-2025-34281

Updated: 2025-10-17T18:59:48.159Z

Status : Awaiting Analysis
Published: 2025-10-17T19:15:37.197
Modified: 2025-10-21T19:31:50.020
Link: CVE-2025-34281

No data.