Stored HTML Injection Vulnerability in Asset List by Nozomi Networks
CVE-2025-40893
What is CVE-2025-40893?
A vulnerability has been identified in the Asset List functionality, stemming from inadequate validation of incoming network traffic data. This flaw allows malicious actors to send tailored network packets that inject HTML tags into asset attributes. When users interact with the affected assets in the Asset List, the injected HTML content is rendered in their browsers. This exploitation can lead to phishing attempts and potential open redirect attacks. Although existing input validation measures and Content Security Policy setups partially mitigate risks of full XSS exploitation and direct data disclosure, the vulnerability remains a concern for user safety.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CMC 0 < 25.5.0
Guardian 0 < 25.5.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
