CVE-2025-45286 is a cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1, allowing attackers to inject and execute arbitrary web scripts or HTML through crafted payloads, affecting products like httpbingo and go_httpbin. It carries a CVSS score of 6.1 (Medium), indicating a network-based attack with low complexity requiring user interaction, potentially leading to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.18.0CPE matchmatch criteria | cpe:2.3:a:httpbingo:go-httpbin:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.