Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/sefabasnak/Todoistv8896 |
|
History
Thu, 04 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Doist
Doist todoist |
|
| CPEs | cpe:2.3:a:doist:todoist:8486:*:*:*:*:*:*:* | |
| Vendors & Products |
Doist
Doist todoist |
Tue, 02 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Todoist
Todoist todoist |
|
| Vendors & Products |
Todoist
Todoist todoist |
Mon, 01 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-01T00:00:00.000Z
Updated: 2025-12-02T15:41:15.725Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63317
Updated: 2025-12-02T15:40:39.173Z
Status : Analyzed
Published: 2025-12-01T20:15:52.907
Modified: 2025-12-04T18:11:06.880
Link: CVE-2025-63317
No data.