HTML Injection Vulnerability in reNgine Web Application Framework
CVE-2025-24966
What is CVE-2025-24966?
The reNgine framework for automated reconnaissance has a critical vulnerability in its 'Add Target' feature. This vulnerability arises from inadequate validation of user inputs in the 'Target Organization' and 'Target Description' fields, enabling attackers to inject malicious HTML code. When executed, this code can lead to unauthorized actions or the theft of sensitive information. As a result, user trust and the integrity of the framework may be severely compromised. All versions of reNgine up to 2.2.0 are affected, and users should stay vigilant for updates aimed at resolving this issue, as there are currently no known workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rengine <= 2.2.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
