groupsession.jp
https://groupsession.jp/info/info-news/security20251208 CVE-2025-61987
MEDIUM
Record summary
CVE-2025-61987 has a selected CVSS score of 6.9 (medium).
Description
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
GroupSession Free editionBrowse Japan Total System Co.,Ltd. / GroupSession Free edition | CVE List | prior to ver5.3.0 | affected |
GroupSession ZIONBrowse Japan Total System Co.,Ltd. / GroupSession ZION | CVE List | prior to ver5.3.2 | affected |
GroupSession byCloudBrowse Japan Total System Co.,Ltd. / GroupSession byCloud | CVE List | prior to ver5.3.3 | affected |
References
3jvn.jp
https://jvn.jp/en/jp/JVN19940619 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-61987