Back to Database
Status published
Medium
CVE-2025-55135
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS...
Vulnerability Description
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55135
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/agorafoundation/agora/pull/556
- https://github.com/agorafoundation/agora/commit/690ce56f254af01375b6033e53a80f14d7cc002e
- https://github.com/agorafoundation/agora/blob/90f7f9c217cf1d5dc9d27f5695cd65b61a4c4759/server/controller/userController.js#L332-L336
- https://github.com/Msfv3n0m/vulnerability-research/tree/main/CVE-2025-55135
Affected Vendor
Agora Foundation
View all reports →Affected Software
Agora
Vulnerable Versions:
0
Timeline
Official Publish:
August 7th, 2025
Last Modified:
August 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N