Skip to content

Conversation

@MMAKINGDOM
Copy link

Updates

  • Affected products
  • CVSS v3
  • CWEs
  • Description
  • Severity
  • Summary

Comments
Based on the original repository; https://github.com/MMAKINGDOM/CVE-2025-63420
Also, The vulnerability doesn't lead to JavaScript execution due to the CSP, and as mentioned on the repository. only HTML execution.

Regarding the "Affected products" Sections, there isn't any accurate options, givin that, i've set it to Maven.

@github-actions github-actions bot changed the base branch from main to MMAKINGDOM/advisory-improvement-6405 November 10, 2025 07:01
@helixplant
Copy link

Hi @MMAKINGDOM, thank you for taking the time to supply this data.

We are unable to make the proposed changes since this is an unreviewed advisory. We can provide support to advisories that are within one of the GitHub Advisory Database's supported ecosystems.

If you are looking to update the CVE, please reach out to the assigning CNA directly.

@helixplant helixplant closed this Nov 12, 2025
@github-actions github-actions bot deleted the MMAKINGDOM-GHSA-4pqv-hw6c-g45v branch November 12, 2025 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants