Description

Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.

INFO

Published Date :

2025-12-04T18:16:56.582Z

Last Modified :

2025-12-04T20:00:41.734Z

Source :

Sonatype
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13488 vulnerability.

Vendors Products
Sonatype
  • Nexus Repository Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-13488.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability