CVE-2025-32960 Details
Description
The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the browser. For a successful attack, a malicious file needs to be uploaded beforehand. This issue has been patched in version 7.2.7. A workaround is provided on the Jmix documentation website.
A cross-site scripting (XSS) vulnerability has been identified in the CUBA REST API add-on versions 7.1.1 prior to 7.2.7, as well as in the Jmix REST API component versions 1.0.0 through 1.6.1 and 2.0.0 through 2.3.4. This vulnerability allows for the execution of malicious JavaScript in the browser by manipulating the 'FileRef' parameter to return a 'Content-Type' header of 'text/html', particularly if the file name ends with '.html'. For exploitation, a harmful file must be uploaded to the file storage beforehand. The issue has been addressed in CUBA REST API add-on version 7.2.7 and in Jmix versions 1.6.2 and 2.4.0.
Users can upgrade to CUBA REST API add-on version 7.2.7 or Jmix versions 1.6.2 and 2.4.0. For those unable to upgrade, the '/files' REST endpoint can be disabled to mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2025CISA-ADP
Assessed Apr 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.jmix.io/jmix/files-vulnerabilities.html | [email protected] | BundleRemedyVendor |
| https://docs.jmix.io/jmix/files-vulnerabilities.html#disable-files-endpoint-in-cuba-application | [email protected] | AdvisoryBundleRemedyVendor |
| https://github.com/cuba-platform/restapi/commit/b3d599f6657d7e212fdb134a61ab5e0888669eb1 | [email protected] | Source CodeVendor |
| https://github.com/cuba-platform/restapi/security/advisories/GHSA-88h5-34xw-2q56 | [email protected] | AdvisoryBundleRemedyVendor |
| https://github.com/jmix-framework/jmix/security/advisories/GHSA-x27v-f838-jh93 | [email protected] | AdvisoryNot ApplicableVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Jmix | All versions |
CPE
Remediation
| |
| CUBA | >= 6.2.0, <= 7.2.22 (semver) |
CPE
Remediation
| |
| CUBA REST API add-on | All versions |
CPE
Remediation
| |
| CUBA JPA Web API add-on | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2025 | New CVE Received | [email protected] |
Volerion