Junglewise Threat Intelligence

CVE-2025-9095: ExpressGateway Cross-Site Scripting in lib/rest/routes/users.js

CVE-2025-9095 · Severity: low · CVSS 3.1 · Published 2025-08-18

Vendors: npm.

Executive brief

ExpressGateway is an API gateway and middleware platform that routes HTTP requests. A cross-site scripting (XSS) vulnerability in its user management interface allows a logged-in user to unknowingly execute malicious JavaScript code in their browser, potentially stealing session data or credentials. The vulnerability requires an attacker to trick an authenticated user into viewing a specially crafted URL, making it a targeted attack with limited but real security impact.

Technical details

This is a reflected cross-site scripting (XSS / CWE-79) vulnerability in the REST endpoint at lib/rest/routes/users.js. User-supplied input in the HTTP request is reflected into the response without proper HTML escaping or sanitization, allowing arbitrary JavaScript injection. The attack is network-reachable but requires an authenticated user (low-privileged context) and user interaction—specifically, the victim must click a malicious link or visit a crafted URL. An attacker can achieve session hijacking, credential theft, or UI manipulation of the affected page. No patch information was disclosed in the advisory.

Affected products

  • ExpressGateway express-gateway up to 1.16.10

Timeline

  • 2025-08-18: disclosed
  • 2025-08-19: advisory: GitHub security advisory published

References

Related threats