Medium severity6.1NVD Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2025-65790
CVE-2025-65790
Description
A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline element, the browser executes the attacker-controlled JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:realtimelogic:fuguhub:8.1:*:*:*:*:windows:*:*
Patches
Vulnerability mechanics
References
1- fuguhub.comnvdProduct
News mentions
0No linked articles in our index yet.