CVE-2025-11146

Publication date

2025-09-29 09:26:35

Family

INCIBE

State

PUBLISHED

Description

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.