CVE-2025-54597

Name
CVE-2025-54597
Description
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/linuxserver/Heimdall/commit/d1a96dd752ba30dc56380400dd2587d8abb8e9d1
cve@mitre.org https://github.com/linuxserver/Heimdall/compare/v2.7.2...v2.7.3

Match rules

CPE URI Source package Min version Max version
heimdall >= 0 < 2.7.3
cpe:2.3:a:linuxserver:heimdall_application_dashboard:*:*:*:*:*:*:*:* heimdall_application_dashboard >= None < 2.7.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
heimdall edge-community 2.2.2-r0 Henrik Grimler <henrik@grimler.se> possibly vulnerable
heimdall edge-community 2.1.0-r0 Henrik Grimler <henrik@grimler.se> possibly vulnerable
heimdall 3.22-community 2.2.2-r0 Henrik Grimler <henrik@grimler.se> possibly vulnerable
heimdall 3.22-community 2.1.0-r0 Henrik Grimler <henrik@grimler.se> possibly vulnerable