Vulnerability Description
Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Doist | Todoist | 8486 |
Related Weaknesses (CWE)
References
- https://github.com/sefabasnak/Todoistv8896ExploitThird Party Advisory
FAQ
What is CVE-2025-63317?
CVE-2025-63317 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a t...
How severe is CVE-2025-63317?
CVE-2025-63317 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63317?
Check the references section above for vendor advisories and patch information. Affected products include: Doist Todoist.