Medium severity5.0OSV Advisory· Published May 27, 2025· Updated Jun 17, 2026
CVE-2025-5198
CVE-2025-5198
Description
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:kubernates:*:*
Patches
Vulnerability mechanics
References
3- access.redhat.com/security/cve/CVE-2025-5198nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/stackrox/stackrox/pull/13336nvd
News mentions
0No linked articles in our index yet.