Security Advisory

CVE-2025-60916Unfiltered charge parameter in /overview/network/ – DOM-based XSS

OpenAtlas · Austrian Academy of Sciences (ÖAW)

CVE published 24 Nov 2025 · discovered 8 Aug 2025

Overview

The same network overview contained a second XSS vector through the charge parameter. Client-side processing could turn this data into executable content.

Technical findings

This finding also affects /overview/network/, this time through the charge parameter. Its value reached a DOM rendering path without being neutralized for the destination context.

The result was a link whose payload was evaluated by the browser when opened. The core flaw is simple: a URL parameter could cross the boundary between data and executable content.

Versions through 8.12.0 are affected. The fix was released in OpenAtlas 8.13.0.

Why it matters

An attack requires a crafted link and someone to open it. Once executed, the payload runs in the OpenAtlas origin and therefore shares the application’s browser context.

Potential impact

  • DOM-based XSS caused by an unfiltered parameter.

Remediation

  • Upgrade to OpenAtlas 8.13.0 or later.
  • Strictly limit the charge parameter to expected values and data types.
  • Avoid unsafe DOM sinks; use safe APIs such as textContent for untrusted data.
  • Use CSP as an additional safeguard, not as a replacement for safe handling of output.

Affected and fixed versions

Affected<= 8.12.0
Fixed / vendor-confirmed8.13.0

References

Related OpenAtlas research