Vulnerability Description
ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, there is a stored Cross-Site Scripting (XSS) vulnerability in the dashboard, which can exploited when a user clicks on a malicious bookmark, made vulnerable by the lack of scheme filtering. This is fixed in version 0.6.8.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matiasdesuu | Thinkdashboard | < 0.6.8 |
Related Weaknesses (CWE)
References
- https://github.com/MatiasDesuu/ThinkDashboard/commit/16976263b22a4b0526b2c7c3029Patch
- https://github.com/MatiasDesuu/ThinkDashboard/security/advisories/GHSA-57f2-rhxmExploitVendor Advisory
FAQ
What is CVE-2025-64177?
CVE-2025-64177 is a vulnerability with a CVSS score of 5.4 (MEDIUM). ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, there is a stored Cross-Site Scripting (XSS) vulnerability in the dashboard, which...
How severe is CVE-2025-64177?
CVE-2025-64177 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64177?
Check the references section above for vendor advisories and patch information. Affected products include: Matiasdesuu Thinkdashboard.