CVE-2025-15095

LOW

postmanlabs httpbin <= 0.6.1 - Cross-Site Scripting in core.py

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.338424
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.338424
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.709002
Issue Tracking exploit issue-tracking
https://github.com/postmanlabs/httpbin/issues/735

Scores

CVSS v3 3.5
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (2)
postmanlabs/httpbin 0.6.0
postmanlabs/httpbin 0.6.1
Published Dec 26, 2025
Tracked Since Feb 18, 2026