CVE-2025-49126 - CVE House
Back to Database
Status published High CVE-2025-49126

Visionatrix Vulnerable to Reflected XSS Leading to Exfiltration of Secrets

Vulnerability Description

Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the get_swagger_ui_html function from FastAPI. This function does not encode or sanitize its arguments before using them to generate the HTML for the swagger documentation page and is not intended to be used with user-controlled arguments. Any user of this application can be targeted with a one-click attack that can takeover their session and all the secrets that may be contained within it. This issue has been patched in version 2.5.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49126

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Visionatrix

View all reports →

Affected Software

Visionatrix
Vulnerable Versions:
>= 1.5.0, < 2.5.1

Timeline

Official Publish: June 23rd, 2025
Last Modified: June 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L

Weaknesses (CWE)