CVE-2025-46655 Details
Description
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers.
A vulnerability exists in CodiMD versions through 2.5.4, where the Content Security Policy (CSP) intended to protect against Cross-Site Scripting (XSS) in uploaded SVG files can be bypassed. This issue arises in scenarios involving different-origin file storage, such as AWS S3. While it may be considered user error to host untrusted JavaScript on AWS without proper CSP headers, the vulnerability highlights a flaw in CodiMD's handling of file uploads and CSP enforcement.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 26, 2025CISA-ADP
Assessed Apr 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hackmdio/codimd/issues/1910 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/hackmdio/codimd/issues/1910 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/zast-ai/vulnerability-reports/blob/main/formidable/file_upload/report.md | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-424 | Improper Protection of Alternate Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CodiMD | <= 2.2.0 (semver) >= 2.5.4, <= 2.2.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2025 | CVE Modified | CISA-ADP |
| Apr 26, 2025 | New CVE Received | [email protected] |
Volerion