Cross-Site Scripting in Promptcraft Forge Studio by Marcelo Tessaro
CVE-2025-58353
What is CVE-2025-58353?
Promptcraft Forge Studio, a toolkit for managing LLM-powered applications, is vulnerable due to improper input sanitization using regex blacklisting techniques. The toolkit's reliance on multi-character tokens means that when user inputs are sanitized, harmful executables can still be present within the sanitized value. This vulnerability allows an attacker to inject executable scripts into href or src attributes, potentially leading to Cross-Site Scripting (XSS) attacks. Currently, no fix has been released for this security flaw, highlighting the importance of developers employing safer input sanitization methods.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
promptcraft-forge-studio >= 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
