Origin Validation Error in Chatwoot Widget by Chatwoot
CVE-2025-12245
What is CVE-2025-12245?
A vulnerability has been identified in the Chatwoot Widget, specifically in the initPostMessageCommunication function located in the app/javascript/sdk/IFrameHelper.js file. This flaw allows for improper validation of the baseUrl argument, leading to potential origin validation errors. Such vulnerabilities can be exploited remotely by an attacker, enabling unauthorized access or actions within the application. Although the vendor was approached regarding this issue, there has been no response to date. Users are advised to take preventive measures until a patch is released.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
chatwoot 4.0
chatwoot 4.1
chatwoot 4.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
