Unauthorized JavaScript Execution in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20367
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 1 October 2025
What is CVE-2025-20367?
In specific versions of Splunk Enterprise and Splunk Cloud Platform, a vulnerability allows low-privileged users to exploit the dataset.command parameter of the /app/search/table endpoint. By crafting a malicious payload, the users could execute unauthorized JavaScript code in the browsers of other users, potentially compromising user data and security. This highlights the importance of stringent input validation to protect against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Cloud Platform 9.3.2411 < 9.3.2411.109
Splunk Cloud Platform 9.3.2408 < 9.3.2408.119
Splunk Cloud Platform 9.2.2406 < 9.2.2406.122
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved