CVE Database
/

CVE-2025-41085

Back to search

CVE-2025-41085

Published: Feb 4, 2026

Modified: Feb 4, 2026

PUBLISHED

Description

Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request to '/api/v1/user-avatar', which are then stored on the server and executed in the context of any user accessing the compromised resource.

VendorProductVersions

Apidog

Apidog Web Platform

affected
2.7.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now