CVE-2025-71385

Name
CVE-2025-71385
Description
Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and serves the response with Content-Type image/svg+xml. An attacker can craft a URL such as /api/v2/ilove.svg?love=<script>...</script>; when a victim navigates to it the injected script executes in the victim browser in the origin of the Netdata instance (reflected cross-site scripting). These endpoints are registered with HTTP_ACL_NOCHECK and anonymous access and, because bearer-token protection is disabled by default, are reachable without authentication on a default Netdata agent. The issue was resolved by removing the ilove endpoint.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/netdata/netdata/commit/f82554fe9b21b5ae51a8663a3f4ddce84cac16af
disclosure@vulncheck.com https://github.com/netdata/netdata/pull/19919
disclosure@vulncheck.com https://github.com/netdata/netdata/releases/tag/v2.3.1
disclosure@vulncheck.com https://www.vulncheck.com/advisories/netdata-reflected-cross-site-scripting-via-love-parameter-in-ilove-svg-endpoint

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:netdata:netdata:*:*:*:*:*:*:*:* netdata >= None < 2.3.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
netdata edge-community 1.47.5-r22 None possibly vulnerable
netdata edge-community 1.47.5-r21 None possibly vulnerable
netdata edge-community 1.47.5-r20 None possibly vulnerable
netdata edge-community 1.47.5-r19 None possibly vulnerable
netdata edge-community 1.47.5-r18 None possibly vulnerable
netdata edge-community 1.47.5-r17 None possibly vulnerable
netdata edge-community 1.47.5-r16 None possibly vulnerable
netdata edge-community 1.47.5-r15 None possibly vulnerable
netdata edge-community 1.47.5-r14 None possibly vulnerable
netdata edge-community 1.47.5-r13 None possibly vulnerable
netdata edge-community 1.47.5-r12 None possibly vulnerable
netdata edge-community 1.47.5-r11 None possibly vulnerable
netdata edge-community 1.47.5-r10 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r9 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r8 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r7 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r6 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r5 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r4 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r3 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.47.5-r2 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata edge-community 1.43.2-r1 Kevin Daudt <kdaudt@alpinelinux.org> possibly vulnerable
netdata 3.24-community 1.47.5-r22 None possibly vulnerable