Skip to main content
Vulnerability Database/CVE-2025-66420

CVE-2025-66420: Tryton SAO XSS Vulnerability

CVE-2025-66420 is a cross-site scripting flaw in Tryton SAO that allows attackers to inject malicious scripts via HTML attachments. This article covers technical details, affected versions, security impact, and mitigation.

Published:

CVE-2025-66420 Overview

CVE-2025-66420 is a stored cross-site scripting (XSS) vulnerability in Tryton sao (also known as tryton-sao), the web client for the Tryton business application platform. Versions before 7.6.9 allow an authenticated user to upload an HTML attachment containing malicious script content. When another user opens the attachment through the web client, the browser renders the HTML in the application's origin, enabling script execution in the victim's session. The issue is tracked as [CWE-79] and is fixed in versions 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

Critical Impact

Attackers with a low-privilege Tryton account can execute arbitrary JavaScript in another user's browser session, enabling session theft, data exfiltration, and actions performed on behalf of the victim.

Affected Products

  • Tryton sao (tryton-sao) versions before 6.0.67
  • Tryton sao versions 7.0.0 through 7.0.37, 7.4.0 through 7.4.18
  • Tryton sao versions 7.6.0 through 7.6.8

Discovery Timeline

  • 2025-11-30 - CVE-2025-66420 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66420

Vulnerability Analysis

The vulnerability resides in how Tryton sao serves HTML file attachments to end users. The web client returns HTML attachments to the browser without neutralizing active content or forcing a download disposition. As a result, JavaScript embedded in the attachment executes within the same origin as the Tryton web application. This gives an attacker access to session cookies, CSRF tokens, and any authenticated API the victim can reach.

Because exploitation requires an authenticated user to upload the file and a second user to open it, the attack falls into the stored XSS category with a user interaction requirement. The scope change reflected in the metric vector indicates that script execution in the browser affects resources beyond the vulnerable component itself, such as the user's session and any linked business modules.

Root Cause

The root cause is missing output sanitization and an unsafe Content-Type or Content-Disposition on attachment delivery. Tryton sao serves user-supplied HTML with a renderable MIME type instead of forcing application/octet-stream or applying a strict Content-Security-Policy on the attachment endpoint. This falls under [CWE-79]: Improper Neutralization of Input During Web Page Generation.

Attack Vector

An authenticated attacker uploads an HTML file as an attachment to any record accessible in their Tryton workspace. The attachment contains a <script> payload or an event handler such as onload. When a second authenticated user opens or previews the attachment through the sao web client, the browser executes the payload in the Tryton origin. The attacker can then hijack the victim's session, submit requests as the victim, or read sensitive business data.

The vulnerability is described in prose only. Refer to the Tryton Security Release Discussion and Heptapod Issue #14290 for upstream technical details.

Detection Methods for CVE-2025-66420

Indicators of Compromise

  • Attachments with .html, .htm, .svg, or .xhtml extensions uploaded to Tryton records by non-administrative users
  • HTTP responses from the sao attachment endpoint serving user-uploaded content with Content-Type: text/html
  • Outbound requests from user browsers to unfamiliar domains immediately after opening a Tryton attachment

Detection Strategies

  • Inspect stored attachments in the Tryton database for HTML files containing <script>, javascript:, or inline event handler attributes such as onerror and onload
  • Review web server access logs for GET requests to attachment routes that return text/html responses to authenticated sessions
  • Correlate attachment uploads with subsequent anomalous API calls or privilege changes performed by the account that opened the file

Monitoring Recommendations

  • Alert on any Tryton sao version below 7.6.9, 7.4.19, 7.0.38, or 6.0.67 detected in the environment
  • Monitor browser-side Content Security Policy violation reports originating from Tryton application domains
  • Track new user account activity that uploads attachments shortly after account creation, a common pattern for stored XSS staging

How to Mitigate CVE-2025-66420

Immediate Actions Required

  • Upgrade Tryton sao to 7.6.9, 7.4.19, 7.0.38, or 6.0.67 depending on the deployed release branch
  • Audit existing attachments and remove or quarantine any HTML files uploaded before the patch
  • Rotate session cookies and API tokens for users who may have opened untrusted HTML attachments

Patch Information

The Tryton project fixed the issue in sao versions 7.6.9, 7.4.19, 7.0.38, and 6.0.67. Details are published in the Tryton Security Release Discussion and tracked in Heptapod Issue #14290. Administrators should apply the patched release matching their current branch rather than performing a major version jump.

Workarounds

  • Configure the reverse proxy to force Content-Disposition: attachment on responses from the Tryton sao attachment endpoint until patching is complete
  • Apply a strict Content-Security-Policy header such as default-src 'none'; sandbox on attachment responses to block inline script execution
  • Restrict attachment upload permissions to trusted roles until the upgrade is deployed
bash
# Nginx workaround: force download disposition on Tryton attachment responses
location ~ ^/[^/]+/attachment/ {
    proxy_pass http://tryton_sao_backend;
    proxy_hide_header Content-Disposition;
    add_header Content-Disposition "attachment" always;
    add_header Content-Security-Policy "default-src 'none'; sandbox" always;
    add_header X-Content-Type-Options "nosniff" always;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.