CVE-2025-3019
CVSS 3.1 Score 3.1 of 10 (low)
Details
Summary
CVE-2025-3019 is a cross-site scripting (XSS) vulnerability affecting the KNIME Business Hub. This issue lies in the nuxt-security module, which is widely used in KNIME Business Hub's web pages. If a user clicks on a malicious link or opens an infected webpage, attackers can execute arbitrary Java Script with the user's permissions, potentially leading to data loss or modification. There are currently no workarounds for this vulnerability, and KNIME strongly advises users to update to KNIME Business Hub versions 1.13.3 or later, or 1.12.4 or later to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.