Cross-Site Scripting Vulnerability in MQTTX Desktop Client by EMQX
CVE-2025-62413
6.1MEDIUM
What is CVE-2025-62413?
MQTTX, a desktop client for MQTT 5.0, has a vulnerability where improper handling of MQTT message payloads allows Cross-Site Scripting (XSS). This flaw exists in MQTTX version 1.12.0, enabling attackers to execute arbitrary scripts through malicious payloads that are rendered in the message viewer. The exploitation risk is significant, particularly in untrusted or multi-tenant environments, where the control over message content may be limited. The issue was resolved in version 1.12.1.
Affected Version(s)
MQTTX = 1.12.0