CVE-2025-55135

MEDIUM

Agora Foundation Agora fall23-Alpha1 - XSS

Title source: llm
STIX 2.1

Description

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

Scores

CVSS v3 6.4
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
Agora Foundation/Agora < 690ce56f254af01375b6033e53a80f14d7cc002e
Published Aug 07, 2025
Tracked Since Feb 18, 2026