Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. privatebin/privatebin
  4. ›
  5. CVE-2025-62796

CVE-2025-62796: PrivateBin is missing HTML sanitization of attached filename in file size hint

October 28, 2025 (updated October 29, 2025)

We’ve identified an HTML injection/XSS vulnerability in PrivateBin service that allows the injection of arbitrary HTML markup via the attached filename. Below are the technical details, PoC, reproduction steps, impact, and mitigation recommendations.

Recommend action: As the vulnerability has been fixed in the latest version, users are strongly encouraged to upgrade PrivateBin to the latest version and check that a strong CSP header, just as the default suggested one, is delivered.

Summary of the vulnerability: The attachment_name field containing the attached file name is included in the object that the client encrypts and is eventually rendered in the DOM without proper escaping.

References

  • github.com/PrivateBin/PrivateBin
  • github.com/PrivateBin/PrivateBin/commit/c4f8482b3072be7ae012cace1b3f5658dcc3b42e
  • github.com/PrivateBin/PrivateBin/pull/1550
  • github.com/PrivateBin/PrivateBin/security/advisories/GHSA-867c-p784-5q6g
  • github.com/advisories/GHSA-867c-p784-5q6g
  • nvd.nist.gov/vuln/detail/CVE-2025-62796

Code Behaviors & Features

Detect and mitigate CVE-2025-62796 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.7.7 before 2.0.2

Fixed versions

  • 2.0.2

Solution

Upgrade to version 2.0.2 or above.

Impact 5.8 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/privatebin/privatebin/CVE-2025-62796.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Nov 2025 00:20:39 +0000.