CVE 8.2 HIGH

Cross-Site Request Forgery (CSRF) Leading to Account Takeover via SVG File Upload_CVE-2025-14202

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N

Description

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the admin’s browser, retrieves the CSRF token, and sends a request to change the admin's password resulting in a full account takeover.

Basic Information

ID CVE-2025-14202
Source Gridware
Published Dec 17, 2025 at 23:35

Affected Product

Vendor Linkding
Product LinkDing
Version 1.44.1
Affected Versions Linkding LinkDing 1.44.1

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.