Junglewise Threat Intelligence

CVE-2025-67438: Sync-in Server stored cross-site scripting in SVG file upload

CVE-2025-67438 · Severity: medium · CVSS 4 · Published 2026-02-20

Technologies: Sync-in Server. Vendors: npm.

Executive brief

Sync-in Server is a collaborative file management platform that allows users to upload and share documents. An authenticated attacker can upload a malicious SVG file that executes arbitrary JavaScript in other users' browsers when they view it, potentially stealing session cookies and sensitive information. This vulnerability requires user authentication and victim interaction to trigger.

Technical details

This is a stored cross-site scripting (CWE-79) vulnerability in Sync-in Server prior to version 1.9.3. An authenticated attacker can upload a crafted SVG file containing embedded malicious JavaScript. When other users access or preview the SVG file, the browser executes the injected script in their security context, allowing session hijacking and data theft. The root cause was improper file content-type handling; the fix involves serving uploaded files with the `Content-Disposition: attachment` header to force download behavior instead of in-browser rendering. Authentication is required, but no special privileges are needed beyond user login status.

Affected products

  • Sync-in Server before 1.9.3

Timeline

  • 2026-02-20: disclosed
  • 2025-12-07: patched: Fix committed on December 7, 2025; patched in version 1.9.3

References

Related threats