CVE-2025-49126

Visionatrix Vulnerable to Reflected XSS Leading to Exfiltration of Secrets

Description

Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the get_swagger_ui_html function from FastAPI. This function does not encode or sanitize its arguments before using them to generate the HTML for the swagger documentation page and is not intended to be used with user-controlled arguments. Any user of this application can be targeted with a one-click attack that can takeover their session and all the secrets that may be contained within it. This issue has been patched in version 2.5.1.

Category

8.8
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.04%
Affected: Visionatrix Visionatrix
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-49126?
CVE-2025-49126 has been scored as a high severity vulnerability.
How to fix CVE-2025-49126?
To fix CVE-2025-49126, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2025-49126 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-49126 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-49126?
CVE-2025-49126 affects Visionatrix Visionatrix.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.