CVE-2025-3801 describes a problematic Cross-Site Scripting (XSS) vulnerability in songquanpeng one-api versions up to 0.6.10, specifically within the System Setting Handler when manipulating the Homepage Content/About System/Footer arguments. This vulnerability has a low CVSS score of 2.4, indicating a remote attack vector with high privileges required and low impact (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N). While the exploit has been publicly disclosed, there is no evidence of active exploitation, no known exploit modules in common frameworks like Metasploit or Nuclei, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Songquanpeng | One-Api | 0.6.0, 0.6.1, 0.6.10, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 0.6.8, 0.6.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.