Description
Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.
INFO
Published Date :
2025-12-04T18:16:56.582Z
Last Modified :
2025-12-04T20:00:41.734Z
Source :
Sonatype
AFFECTED PRODUCTS
The following products are affected by CVE-2025-13488 vulnerability.
| Vendors | Products |
|---|---|
| Sonatype |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-13488.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability