CVE-2025-65754

MEDIUM

Algernon < 1.17.5 - Cross-Site Scripting via Filename Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-65754. PoCs published by Bnyt7.

AI-analyzed exploit summary This PoC demonstrates a stored XSS vulnerability in Algernon 1.17.4, where filenames are not properly sanitized before being rendered in directory listings. The exploit involves creating files with malicious names containing XSS payloads, which execute when accessed via the web interface.

Description

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

Exploits (1)

nomisec WORKING POC
by Bnyt7 · poc
https://github.com/Bnyt7/CVE-2025-65754

This PoC demonstrates a stored XSS vulnerability in Algernon 1.17.4, where filenames are not properly sanitized before being rendered in directory listings. The exploit involves creating files with malicious names containing XSS payloads, which execute when accessed via the web interface.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Algernon 1.17.4
No auth needed
Prerequisites: Access to upload or create files in a directory served by Algernon
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 1.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
algernon_project/algernon 1.17.4
xyproto/algernon 0 - 1.17.5Go
Published Dec 10, 2025
Tracked Since Feb 18, 2026