Medium severity5.4GHSA Advisory· Published Nov 30, 2025· Updated Apr 15, 2026
CVE-2025-66421
CVE-2025-66421
Description
Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tryton-saonpm | >= 7.5.0, < 7.6.11 | 7.6.11 |
tryton-saonpm | >= 7.1.0, < 7.4.21 | 7.4.21 |
tryton-saonpm | >= 7.0.0, < 7.0.40 | 7.0.40 |
tryton-saonpm | < 6.0.69 | 6.0.69 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.