Junglewise Threat Intelligence

CVE-2025-53528: PYSEC-2025-71 - Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version paramet

CVE-2025-53528 · Severity: low · CVSS 3.1 · Published 2025-07-21

Vendors: PyPI.

Executive brief

Cadwyn is a Python framework for building versioned APIs with integrated API documentation. A reflected cross-site scripting (XSS) vulnerability in the /docs endpoint allows unauthenticated attackers to inject malicious JavaScript that executes in a user's browser session. An attacker can trick a user into clicking a crafted link to steal session data, modify documentation pages, or perform unauthorized actions on behalf of the user.

Technical details

The vulnerability is a reflected XSS (CWE-79) in the /docs endpoint's version query parameter. The vulnerable code in the swagger_dashboard and redoc_dashboard functions passes unsanitized user input from the version query parameter directly to FastAPI's get_swagger_ui_html function, which embeds it into a JavaScript string without encoding. An attacker can inject a single quote followed by JavaScript code (e.g., '+ alert(document.domain) +') to escape the string context and execute arbitrary code. The attack requires only network access and user interaction (clicking a malicious link), with no authentication required. The vulnerability affects all versions prior to 5.4.3, which was released as a patch.

Affected products

  • Cadwyn Cadwyn before 5.4.3

Timeline

  • 2025-07-21: disclosed
  • 2025-07-21: patched: Fixed in version 5.4.3

References