PT-2026-68633 · Unknown · Api Publisher

CVE-2025-6508

·

Published

2026-08-06

·

Updated

2026-08-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions API Publisher (affected versions not specified)
Description The Swagger UI Try-out console within the API Publisher documentation allows the loading of an external Swagger API definition URL, which overrides the existing API definitions in the Publisher portal. This flaw allows malicious actors to deceive users into interacting with manipulated API definitions, potentially leading to the exposure of sensitive information or the initiation of unintended requests to backend services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6508

Affected Products

Api Publisher