Cross-Site Scripting Vulnerability in MQTTX Desktop Client by EMQX
CVE-2025-62413

6.1MEDIUM

Key Information:

Vendor

EMQx

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-62413?

MQTTX, a desktop client for MQTT 5.0, has a vulnerability where improper handling of MQTT message payloads allows Cross-Site Scripting (XSS). This flaw exists in MQTTX version 1.12.0, enabling attackers to execute arbitrary scripts through malicious payloads that are rendered in the message viewer. The exploitation risk is significant, particularly in untrusted or multi-tenant environments, where the control over message content may be limited. The issue was resolved in version 1.12.1.

Affected Version(s)

MQTTX = 1.12.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62413 : Cross-Site Scripting Vulnerability in MQTTX Desktop Client by EMQX