Cross-Site Scripting Vulnerability in MQTTX Desktop Client by EMQX
CVE-2025-62413
6.1MEDIUM
What is CVE-2025-62413?
MQTTX, a desktop client for MQTT 5.0, has a vulnerability where improper handling of MQTT message payloads allows Cross-Site Scripting (XSS). This flaw exists in MQTTX version 1.12.0, enabling attackers to execute arbitrary scripts through malicious payloads that are rendered in the message viewer. The exploitation risk is significant, particularly in untrusted or multi-tenant environments, where the control over message content may be limited. The issue was resolved in version 1.12.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MQTTX = 1.12.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
