Medium severity6.1NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026
CVE-2025-67438
CVE-2025-67438
Description
A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a malicious payload, an attacker can access and exfiltrate sensitive information, including the user's session cookies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@sync-in/servernpm | < 1.9.3 | 1.9.3 |
Affected products
3- Sync-in/Sync-in Serverdescription
Patches
Vulnerability mechanics
References
5- github.com/Sync-in/server/releases/tag/v1.9.3nvdPatchRelease NotesWEB
- gist.github.com/x0root/86db30af91bb0e1707eb7e57a049b6adnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-9jmq-xgjm-p8c2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-67438ghsaADVISORY
- github.com/Sync-in/server/commit/a6276d067725637310e4e83a3eee337aae81f439ghsaWEB
News mentions
0No linked articles in our index yet.