Home

Description

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session for any application based on Cadwyn via a one-click attack. The vulnerability has been fixed in version 5.4.3.

PUBLISHED Reserved 2025-07-02 | Published 2025-07-21 | Updated 2025-07-23 | Assigner GitHub_M




HIGH: 7.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 5.4.3
affected

References

github.com/...cadwyn/security/advisories/GHSA-2gxp-6r36-m97r

github.com/...ommit/b424ecd57cd8dabbc8fe39b8f8ccafea629c7728

cve.org (CVE-2025-53528)

nvd.nist.gov (CVE-2025-53528)

Download JSON