Cross-site request forgery in EspoCRM - CVE-2025-59428
Published: April 23, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to create arbitrary user accounts.
The vulnerability exists due to cross-site request forgery in SVG handling when rendering a stored crafted SVG file. A remote user can embed a malicious element in an SVG payload to create arbitrary user accounts.
User interaction is required to render the crafted SVG content.