CVE-2025-9096
LOW3.5EPSS 0.02%ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
Published: 8/18/2025Modified: 9/23/2025
Also known as:GHSA-xfp8-x3j6-h67v
Description
A cross-site scripting (XSS) issue exists in ExpressGateway ≤ 1.16.10 in lib/rest/routes/apps.js. User-controlled data returned by the REST endpoint is not sanitized before being rendered by the admin/UI layer, allowing an authenticated, low-privileged actor to store or reflect a payload that executes in a maintainer’s browser when the resource is viewed. The issue can be triggered remotely over the network and does not impact availability. No vendor fix is available at this time.
Affected packages (1)
- npm/express-gatewayfrom 0, <= 1.16.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | LOW3.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
References (7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-9096
- PATCHhttps://github.com/ExpressGateway/express-gateway
- WEBhttps://github.com/freshfish-hust/my-cves/issues/6
- WEBhttps://github.com/freshfish-hust/my-cves/issues/6#issue-3287078206
- WEBhttps://vuldb.com/?ctiid.320418
- WEBhttps://vuldb.com/?id.320418
- WEBhttps://vuldb.com/?submit.627833