Spoofing attack in eLabFTW - CVE-2025-62793

 

Spoofing attack in eLabFTW - CVE-2025-62793

Published: April 24, 2026


Vulnerability identifier: #VU127372
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62793
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of active content in uploaded SVG files in the SVG file handling functionality when rendering uploaded SVG content inline in the browser. A remote user can upload a crafted SVG file to disclose sensitive information.

User interaction is required to open the SVG URL or a page embedding the uploaded file.


Affected software

eLabFTW

How to mitigate CVE-2025-62793

Install security update from vendor's website.

eLabFTW - update to 5.3.0

External References

Related Security Bulletins