PT-2025-53434 · Postmanlabs · Httpbin

·

CVE-2025-15095

·

Published

2025-12-26

·

Updated

2025-12-26

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions postmanlabs httpbin versions up to 0.6.1
Description A security issue exists in postmanlabs httpbin up to version 0.6.1. The issue involves cross site scripting and affects an unknown function within the httpbin-master/httpbin/core.py file. The attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 0.6.1 should be used.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15095

Affected Products

Httpbin