Critical severity9.0NVD Advisory· Published Oct 16, 2019· Updated Jun 17, 2026
CVE-2019-17625
CVE-2019-17625
Description
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Ramboxnpm | <= 0.6.9 | — |
Affected products
3- Rambox/Ramboxdescription
Patches
Vulnerability mechanics
References
4- github.com/ramboxapp/community-edition/issues/2418nvdExploitIssue TrackingThird Party Advisory
- github.com/advisories/GHSA-2gc6-2h2g-ph48ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-17625ghsaADVISORY
- web.archive.org/web/20211209122051/https://github.com/ramboxapp/community-edition/issues/2418ghsaWEB
News mentions
0No linked articles in our index yet.