Stored HTML Injection in CMC's Sensor Map Functionality
CVE-2025-40895
What is CVE-2025-40895?
A vulnerability within the CMC's Sensor Map functionality allows a malicious authenticated user with administrative privileges to inject harmful HTML tags by improperly validating connected Guardian properties. If the Sensor Map feature is active, this can result in the injected HTML being rendered in the browsers of other CMC users, potentially facilitating phishing attacks. While the existing input validation and Content Security Policy configurations inhibit full XSS exploitation and direct information disclosure, the vulnerability still poses significant risks to user interaction with the affected functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CMC 0 < 25.6.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
