S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Aug 6, 2025

CVE-2025-8191 Scanner

CVE-2025-8191 Scanner - Cross-Site Scripting (XSS) vulnerability in Swagger UI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-8191
2.0
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
P
Affected
mallby macrozheng
1.0.0
Updated Aug 22, 2026View on NVD →
Detail

Swagger UI is a widely utilized tool for API documentation and interaction, developed by SmartBear. It's predominantly used by developers and organizations to detail and test APIs in a structured and interactive manner. The tool simplifies the communication and understanding of API functionalities by providing a visual interface. It is often integrated into web applications to offer live API documentation. By streamlining API exploration and testing, Swagger UI aids in enhancing developers' productivity. Organizations leverage it to ensure their APIs are comprehensible and testable, aligning with industry standards.

The DOM-based Cross-Site Scripting (XSS) vulnerability in Swagger UI allows attackers to inject malicious scripts into the application. Exploiting this vulnerability, which ranges from version 3.14.1 to 3.37.x, attackers can craft specific payloads in configuration URLs processed by Swagger UI. The vulnerability arises due to improper handling of these URLs, allowing JavaScript code execution in a victim's browser context. This form of XSS is particularly insidious as it does not require traditional server requests to execute. The vulnerability exploits the power of modern web browsers' Document Object Model (DOM) handling to carry out malicious activities. Successful exploitation could lead to severe user data leaks or unauthorized actions performed on behalf of the victim.

Technical details reveal that the vulnerable endpoint involves URLs incorporating the `configUrl` parameter. Payloads crafted within this parameter can be leveraged to execute unauthorized JavaScript commands. The vulnerability is notably exacerbated when Swagger UI instances are exposed online with default configurations. The most common method of exploitation involves crafting a malicious URL referencing a harmful Swagger specification hosted elsewhere. The specified XSS payload injected via `configUrl` relies on user interaction to trigger the script execution context. Attackers frequently exploit this by social engineering through phishing attacks or deceptive web pages.

When exploited, this vulnerability can lead to substantial effects including the theft of user session cookies, sensitive information exposure, and unauthorized actions taken on behalf of the victim. It jeopardizes users' privacy and can damage organizational reputations. Exploitations often lead to unauthorized administrative access or manipulation of user accounts. Moreover, affected entities could potentially suffer from data breaches, leading to compliance violations. Users of vulnerable versions may unknowingly facilitate these effects, amplifying the risk through unpatched deployments.

REFERENCES

Solution Advice
  • Update Swagger UI to the latest version beyond 3.37.x.
  • Apply necessary patches provided by SmartBear to mitigate this vulnerability.
  • Restrict public access to Swagger UI instances unless absolutely necessary.
  • Implement Content Security Policies (CSP) to limit execution of unauthorized scripts.
  • Employ web application firewalls to detect and block XSS payloads.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.