Cross-site scripting in jsondiffpatch - CVE-2025-9910

 

Cross-site scripting in jsondiffpatch - CVE-2025-9910

Published: November 21, 2025


Vulnerability identifier: #VU118669
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-9910
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.


Affected software

jsondiffpatch
Astronomer with IBM
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management

How to mitigate CVE-2025-9910

Install updates from vendor's website.

jsondiffpatch - update to 0.7.2
Astronomer with IBM - update to 1.1.0
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12

External References

Related Security Bulletins