VYPR
Medium severity5.5NVD Advisory· Published Mar 28, 2025· Updated Jun 17, 2026

CVE-2025-28097

CVE-2025-28097

Description

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

Affected products

3
  • OneNav/OneNavllm-fuzzy2 versions
    =1.1.0+ 1 more
    • (no CPE)range: =1.1.0
    • cpe:2.3:a:onenav:onenav:1.1.0:*:*:*:*:*:*:*
  • OneNav/OneNavdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.