PT-2026-55285 · Netdata · Netdata

·

CVE-2025-71385

·

Published

2026-07-02

·

Updated

2026-07-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Netdata versions prior to 2.3.1
Description Reflected cross-site scripting occurs when the application reflects the user-supplied love query parameter of the 'api/v2/ilove.svg' and 'api/v3/ilove.svg' endpoints verbatim into a generated SVG document without HTML or XML escaping. The response is served with the Content-Type image/svg+xml, allowing an attacker to execute arbitrary scripts in the victim's browser within the origin of the instance. These endpoints are registered with HTTP ACL NOCHECK and allow anonymous access, meaning they are reachable without authentication on a default agent because bearer-token protection is disabled by default.
Recommendations Update to version 2.3.1 or later. As a temporary workaround, restrict access to the 'api/v2/ilove.svg' and 'api/v3/ilove.svg' endpoints.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71385

Affected Products

Netdata