Cross-Site Scripting Vulnerability in CISA Software Acquisition Guide Supplier Response Web Tool
CVE-2025-67634

4.6MEDIUM

Key Information:

Vendor

Cisa

Vendor
CVE Published:
12 December 2025

What is CVE-2025-67634?

The CISA Software Acquisition Guide Supplier Response Web Tool prior to December 11, 2025, is susceptible to cross-site scripting attacks via improperly handled text fields. Attackers can exploit this vulnerability by persuading users to import a crafted JSON file containing malicious JavaScript. When users interact with the tool and submit their data, the JavaScript code is executed within their browser context, potentially leading to unauthorized actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Software Acquisition Guide Tool 0 < 2025-12-11

Software Acquisition Guide Tool 2025-12-11

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeff Williams, Contrast Security
.