CVE-2025-67078

MEDIUM

agora-project < 25.10 - Cross-Site Scripting via Notify Parameter

Title source: llm
STIX 2.1

Description

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 8.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
agora-project/agora-project < 25.10
Published Jan 15, 2026
Tracked Since Feb 18, 2026