CVE-2025-66421 Overview
CVE-2025-66421 is a Cross-Site Scripting (XSS) vulnerability in Tryton sao (tryton-sao), the JavaScript client for the Tryton open-source business platform. The flaw stems from the client failing to escape completion values rendered in the user interface. An authenticated attacker who can influence completion data can inject script content that executes in another user's browser session. The vulnerability is tracked under [CWE-79] and is fixed in versions 7.6.11, 7.4.21, 7.0.40, and 6.0.69.
Critical Impact
Authenticated attackers can inject arbitrary scripts into completion fields, leading to session compromise, data exposure, or actions performed on behalf of other users within the Tryton web client.
Affected Products
- Tryton sao (tryton-sao) versions before 6.0.69
- Tryton sao versions 7.0.x before 7.0.40, 7.4.x before 7.4.21
- Tryton sao versions 7.6.x before 7.6.11
Discovery Timeline
- 2025-11-30 - CVE-2025-66421 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66421
Vulnerability Analysis
Tryton sao is the SAO (Sao) web client that renders Tryton application data in a browser. The vulnerability resides in the client-side rendering path for completion values, which are suggestion strings returned when a user types into autocomplete-enabled fields. The client inserts these values into the DOM without proper HTML escaping. An attacker able to store malicious content in a field that later surfaces as a completion suggestion can trigger script execution when another user interacts with that field.
The scope change in the CVSS vector reflects that script execution occurs in the victim's authenticated browser context, potentially crossing privilege boundaries between tenants or users of the same Tryton instance. Exploitation requires low privileges and user interaction, since the victim must trigger the completion dropdown containing the attacker-controlled value.
Root Cause
The root cause is missing output encoding when rendering completion values in the Tryton sao client. User-controlled strings reach the DOM via a rendering path that does not neutralize HTML control characters such as <, >, and quotes. This allows arbitrary HTML and JavaScript to be interpreted by the browser rather than displayed as literal text.
Attack Vector
An attacker with authenticated access to a Tryton instance stores a payload containing HTML or script syntax in a record field that is used as a source for autocomplete suggestions. When a second user begins typing into an input bound to that field, the Tryton sao client fetches matching completions and inserts the attacker's payload into the suggestion dropdown. Rendering the unescaped payload executes the script in the victim's session, enabling actions such as session token theft, CSRF-equivalent requests, or UI manipulation. See the Tryton Security Release Discussion and Heptapod Tryton Issue #14363 for upstream details.
Detection Methods for CVE-2025-66421
Indicators of Compromise
- Tryton database records containing HTML tags such as <script>, <img onerror=, or <svg onload= in fields exposed to autocomplete queries.
- Browser console errors or Content Security Policy violations originating from the Tryton sao client domain.
- Unexpected outbound requests from authenticated Tryton sessions to attacker-controlled hosts.
Detection Strategies
- Audit Tryton model fields used in autocomplete lookups for stored strings containing HTML or JavaScript syntax.
- Review web server access logs for sao client requests returning completion payloads with suspicious characters.
- Inspect running Tryton sao versions against the fixed versions 7.6.11, 7.4.21, 7.0.40, and 6.0.69.
Monitoring Recommendations
- Enable and monitor a strict Content Security Policy on the Tryton sao client to log inline script execution attempts.
- Collect browser error telemetry from users accessing the Tryton web client to surface anomalous script activity.
- Alert on administrative or privileged user sessions that generate unusual XHR patterns shortly after loading autocomplete-driven forms.
How to Mitigate CVE-2025-66421
Immediate Actions Required
- Upgrade Tryton sao to version 7.6.11, 7.4.21, 7.0.40, or 6.0.69 depending on the deployed release branch.
- Invalidate active Tryton sessions after patching to force reauthentication.
- Review fields that feed autocomplete and sanitize or remove stored HTML content.
Patch Information
The Tryton project released fixes in tryton-sao versions 7.6.11, 7.4.21, 7.0.40, and 6.0.69. Patch details and the upstream issue are published in Heptapod Tryton Issue #14363 and announced in the Tryton Security Release Discussion.
Workarounds
- Restrict write access to models whose fields are exposed through autocomplete endpoints to trusted users only.
- Deploy a Content Security Policy that disallows inline scripts and restricts script sources to known origins.
- Place the Tryton sao client behind a reverse proxy that strips HTML control characters from completion response bodies until patching is complete.
# Example Content-Security-Policy header for the Tryton sao client
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'";
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.