Cross-Site Scripting Vulnerability in Logseq Developed by Logseq
CVE-2025-56683

9.6CRITICAL

Key Information:

Vendor

Logseq

Status
Vendor
CVE Published:
9 October 2025

What is CVE-2025-56683?

A cross-site scripting (XSS) vulnerability exists within the Logseq application as of version 0.10.9, specifically located in the /app/marketplace.html component. This vulnerability allows attackers to execute arbitrary code by injecting malicious JavaScript through carefully crafted README.md files. Exploiting this flaw could lead to unauthorized actions being performed in the context of a user's session, compromising user data and security.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.