← Vulnerability feed

Vulnerability record · CVE-2025-5198 · published 27 May 2025

CVE-2025-5198: Redhat advanced cluster security cross-site scripting vulnerability

Redhat · Advanced Cluster Security

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.

5.4 CVSS 3.1 Medium EPSS 0.28% · top 81.8% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-5198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed8.8CVE-2022-1902Redhat advanced cluster security exposure of resource to wrong sphere vulnerabilityA flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw …EPSS 1.4%7.8CVE-2024-0406Mholt archiver path traversal vulnerabilityA flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…EPSS 0.93%7.7CVE-2026-44495Axios code injection vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…EPSS 1.0%6.1CVE-2023-4958Redhat advanced cluster security clickjacking vulnerabilityIn Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this…EPSS 0.63%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 94%analysed6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2025-5198), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.