Cross-Site Scripting Vulnerability in CKAN Data Management System
CVE-2025-54384

6.3MEDIUM

Key Information:

Vendor

Ckan

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-54384?

The CKAN data management system was found to have a security flaw in its helpers.markdown_extract() function, which failed to adequately sanitize user input before displaying it on various pages including datasets and resources. This oversight could allow attackers to inject malicious scripts, potentially compromising user sessions and leading to unauthorized access. The issue has since been addressed in CKAN versions 2.10.9 and 2.11.4, which implement necessary sanitization to protect against such attacks.

Affected Version(s)

ckan >= 2.11.0, < 2.11.4 < 2.11.0, 2.11.4

ckan < 2.10.9 < 2.10.9

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.