ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
History

Fri, 24 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Thingsboard
Thingsboard thingsboard
Vendors & Products Thingsboard
Thingsboard thingsboard

Fri, 17 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 18:45:00 +0000

Type Values Removed Values Added
Description ThingsBoard versions < 4.2.1 contain a stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload an SVG file containing malicious JavaScript, which may be executed when the file is rendered in the UI. This issue results from insufficient sanitization and improper content-type validation of uploaded SVG files.
Title ThingsBoard < v4.2.1 SVG Image Stored XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-10-17T18:33:03.941Z

Updated: 2025-10-17T18:59:51.297Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34281

cve-icon Vulnrichment

Updated: 2025-10-17T18:59:48.159Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-17T19:15:37.197

Modified: 2025-10-24T13:27:01.183

Link: CVE-2025-34281

cve-icon Redhat

No data.