CVE-2025-3019

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 549

Summary

CVE-2025-3019 is a cross-site scripting (XSS) vulnerability affecting the KNIME Business Hub. This issue lies in the nuxt-security module, which is widely used in KNIME Business Hub's web pages. If a user clicks on a malicious link or opens an infected webpage, attackers can execute arbitrary Java Script with the user's permissions, potentially leading to data loss or modification. There are currently no workarounds for this vulnerability, and KNIME strongly advises users to update to KNIME Business Hub versions 1.13.3 or later, or 1.12.4 or later to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share