CVE-2025-70060
Description
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in YMFE YApi v1.12.0 allows attackers to inject malicious scripts via improper input neutralization.
Vulnerability
Overview
CVE-2025-70060 describes a cross-site scripting (XSS) vulnerability in YMFE YApi version 1.12.0, an open-source API management platform [1]. The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79) [3]. This allows an attacker to inject arbitrary JavaScript or HTML into the application's pages.
Exploitation
The vulnerability can be exploited by an authenticated or unauthenticated attacker depending on the affected input field. Since YApi allows users to create and manage API documentation, an attacker could inject malicious scripts into project descriptions, interface parameters, or other user-editable fields. When other users view the affected page, the injected script executes in their browser context. No special network position is required beyond access to the YApi instance.
Impact
Successful exploitation leads to stored XSS, enabling the attacker to steal session cookies, perform actions on behalf of the victim, or deface the application. The CVSS v3 score of 5.4 (Medium) reflects the potential for unauthorized data access and partial compromise of confidentiality and integrity.
Mitigation
As of the publication date, no official patch has been released for YApi v1.12.0 [3]. Users are advised to apply strict input validation and output encoding, or consider upgrading to a patched version when available. The YApi project is actively maintained on GitHub [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- YMFE/yapidescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gist.github.com/zcxlighthouse/b9dc0586016699397c476fda02abc0c7nvdThird Party Advisory
News mentions
0No linked articles in our index yet.