CVE-2025-3801
Moderate
one-api Cross-site Scripting vulnerability in github.com/songquanpeng/one-api
one-api Cross-site Scripting vulnerability in github.com/songquanpeng/one-api
Exploit probability
0.3%
Published
April 22, 2025
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2025-3636
View original source
one-api Cross-site Scripting vulnerability in github.com/songquanpeng/one-api
Open Source Vulnerabilities
GHSA-wvcx-j62q-45qw
View original source
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
05 / REFERENCES
Further evidence
- https://github.com/advisories/GHSA-wvcx-j62q-45qw
- https://github.com/yaowenxiao721/Poc/blob/main/One-API/One-API-poc.md
- https://nvd.nist.gov/vuln/detail/CVE-2025-3801
- https://vuldb.com/?ctiid.305655
- https://vuldb.com/?id.305655
- https://vuldb.com/?submit.554702
- https://github.com/songquanpeng/one-api