Security Advisory

CVE-2025-60917XSS via color input fields in /overview/network/

OpenAtlas · Austrian Academy of Sciences (ÖAW)

CVE published 24 Nov 2025 · discovered 8 Aug 2025

Overview

In the OpenAtlas network overview, the color parameter could reach rendered output in a way that executed JavaScript. A crafted link was sufficient; the payload did not have to be stored.

Technical findings

The affected endpoint is /overview/network/. The color parameter came from the request and was inserted into the network view without being handled safely for each output context.

This allowed a link to execute JavaScript in the browser when opened. It is reflected XSS: the payload does not need to be stored in the database.

OpenAtlas versions through 8.12.0 are affected. The issue was fixed in 8.13.0.

Why it matters

The risk is greatest when an authenticated user opens a crafted network-view link. The injected code runs in the OpenAtlas origin; its capabilities depend on the user’s role, session and available features.

Potential impact

  • JavaScript execution within the application’s browser context.

Remediation

  • Upgrade to OpenAtlas 8.13.0 or later.
  • Accept values such as colors only from a narrow allowlist and validate them server-side.
  • Encode dynamic values for the actual HTML, attribute or JavaScript context in which they appear.
  • Add a restrictive Content Security Policy as defense in depth.

Affected and fixed versions

Affected<= 8.12.0
Fixed / vendor-confirmed8.13.0

References

Related OpenAtlas research