Cross-Site Scripting in Promptcraft Forge Studio by Marcelo Tessaro
CVE-2025-58353
8.2HIGH
What is CVE-2025-58353?
Promptcraft Forge Studio, a toolkit for managing LLM-powered applications, is vulnerable due to improper input sanitization using regex blacklisting techniques. The toolkit's reliance on multi-character tokens means that when user inputs are sanitized, harmful executables can still be present within the sanitized value. This vulnerability allows an attacker to inject executable scripts into href or src attributes, potentially leading to Cross-Site Scripting (XSS) attacks. Currently, no fix has been released for this security flaw, highlighting the importance of developers employing safer input sanitization methods.
Affected Version(s)
promptcraft-forge-studio >= 0