CNNVD-202512-455 Information

CNNVD ID

CNNVD-202512-455

CVE-2025-66574

  • CNNVD Published: 2025-12-04

Description (Chinese)

Taiko Alethia是Taiko Labs开源的一个用于实现Taiko Layer 2网络的基于以太坊的ZK-EVM Rollup协议的软件集合。 Taiko Alethia 3.2.41.10.26版本存在跨站脚本漏洞,该漏洞源于Open Object in Tree端点存在跨站脚本注入,可能导致会话劫持和权限提升。

Description (English)

Taiko Alethia is a collection of software based on the ZK-EVM Rollup protocol for achieving the Taiko Layer 2 network. Taiko Alethia 3.2.41.10.26 has a cross-site script loophole, which stems from the injection of cross-site scripts at the Open Object in Tree endpoint, which may lead to the hijacking of conversations and the enhancement of privileges.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Taiko Labs

Published

2025-12-04

Last Modified

2026-02-24

References

https://www.vulncheck.com/advisories/tranzaxis-32411026-stored-cross-site-scripting-xss https://compassplustechnologies.com/ https://www.exploit-db.com/exploits/52086 https://access.redhat.com/security/cve/cve-2025-66574

Share on: