CVE-2025-65790

Publication date

2025-12-22 00:00:00

Family

mitre

State

PUBLISHED

Description

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline