VDB
CVE-2025-70849
CVE-2025-70849
PUBLISHED
CVSS 2.0999999046325684 LOW
Podinfo affected by Arbitrary File Upload that leads to Stored Cross-Site Scripting (XSS)
EPSS 0.02% · 4.0th percentile
Risk Scores
CVSS v4.0
2.0999999046325684
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P
EPSS Score
0.02%
4.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | stefanprodan/podinfo | 0, 0 |
| n/a | n/a | n/a, n/a |
| stefanprodan | podinfo | 0, 0 |
Timeline
- Feb 3, 2026 CVE Published
- Feb 4, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
- Feb 8, 2026 EPSS Score
- Feb 11, 2026 EPSS Score
- Feb 13, 2026 EPSS Score
- Feb 15, 2026 EPSS Score
- Feb 15, 2026 PoC Published
- Feb 17, 2026 EPSS Score
- Feb 19, 2026 EPSS Score
- Feb 22, 2026 EPSS Score
- Feb 24, 2026 EPSS Score
References
- https://gist.github.com/kazisabu/27f3e272f474005001a9ecd2c258dbea url
- https://nvd.nist.gov/vuln/detail/CVE-2025-70849 advisory
- https://github.com/stefanprodan/podinfo/pull/463 url
- https://github.com/stefanprodan/podinfo/commit/83deb7fcb7421f2d01eeb7475b18d72f16084aed url
- https://github.com/stefanprodan/podinfo package
- https://github.com/stefanprodan/podinfo/releases/tag/6.11.1 url