CVE-2025-63785 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the text editor feature of Onlook web application version 0.2.32. It arises from improper sanitization of user input, allowing malicious HTML and script injection into the DOM via innerHTML during text element editing. With a CVSS score of 6.1 (Medium), this vulnerability can be exploited by an unauthenticated attacker via a low-complexity user interaction, leading to arbitrary script execution within the user's session. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.32CPE matchmatch criteria | cpe:2.3:a:onlook:onlook:0.2.32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.