Security Advisory

CVE-2025-57292

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-26 00:00:00
Last updated 2025-09-26 15:20:12
Assigner mitre
State PUBLISHED

Description

Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.