VYPR
Medium severity5.0OSV Advisory· Published May 27, 2025· Updated Jun 17, 2026

CVE-2025-5198

CVE-2025-5198

Description

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Stackrox/StackroxOSV3 versions
    3.65.x, 3.67.x, 3.68.x, …+ 2 more
    • (no CPE)range: 3.65.x, 3.67.x, 3.68.x, …
    • cpe:2.3:a:stackrox:stackrox:-:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:kubernates:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.