Cross-Site Scripting Vulnerability in CISA Software Acquisition Guide Supplier Response Web Tool
CVE-2025-67634
What is CVE-2025-67634?
The CISA Software Acquisition Guide Supplier Response Web Tool prior to December 11, 2025, is susceptible to cross-site scripting attacks via improperly handled text fields. Attackers can exploit this vulnerability by persuading users to import a crafted JSON file containing malicious JavaScript. When users interact with the tool and submit their data, the JavaScript code is executed within their browser context, potentially leading to unauthorized actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Software Acquisition Guide Tool 0 < 2025-12-11
Software Acquisition Guide Tool 2025-12-11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
