CVE-2025-66561 Overview
CVE-2025-66561 is a Stored Cross-Site Scripting (XSS) vulnerability in SysReptor, a customizable pentest reporting platform developed by Syslifters. The flaw affects all versions prior to 2025.102 and allows authenticated users to upload malicious JavaScript files through the web UI. When other logged-in users interact with the uploaded content, the injected script executes in their browser session. The vulnerability is tracked under CWE-79 and is fixed in release 2025.102.
Critical Impact
An authenticated attacker can execute arbitrary JavaScript in the context of other logged-in SysReptor users, enabling session hijacking, data theft, or unauthorized actions on the platform.
Affected Products
- Syslifters SysReptor versions prior to 2025.102
- All deployments where authenticated users can upload files through the web UI
- Self-hosted and cloud SysReptor instances running vulnerable builds
Discovery Timeline
- 2025-12-04 - CVE-2025-66561 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66561
Vulnerability Analysis
SysReptor is a collaborative pentest reporting platform where users upload evidence, screenshots, and supporting files as part of engagement reporting. The vulnerability stems from insufficient sanitization of uploaded JavaScript files served back through the web UI. An authenticated user with permission to upload files can store a payload that later executes in the browser of any user who accesses the file. Because the payload runs within the authenticated origin, it inherits the victim's session context and privileges.
The scope-changed impact reflected in the CVSS vector indicates that the injected script can affect resources beyond the vulnerable component itself. Consequences include exfiltration of report data, theft of session tokens, forced actions on behalf of the victim, and lateral movement across pentest projects shared by multiple team members.
Root Cause
The root cause is improper handling of file content types or missing Content Security Policy (CSP) enforcement when serving user-uploaded files. Uploaded JavaScript is rendered or executed by the browser instead of being served as inert attachments. The fix in version 2025.102 addresses the unsafe file-serving behavior.
Attack Vector
Exploitation requires an authenticated account with upload privileges and user interaction from a victim (a logged-in user must open the malicious file). The attack is delivered over the network against the SysReptor web interface. No exploit code is publicly available at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Refer to the GitHub Security Advisory GHSA-64vw-v5c4-mgvm for vendor technical details.
Detection Methods for CVE-2025-66561
Indicators of Compromise
- Uploaded files with .js, .html, .svg, or other browser-executable MIME types in SysReptor project attachments
- Unusual outbound requests from analyst browsers to attacker-controlled domains shortly after opening report attachments
- Unexpected session token usage from atypical geolocations or user agents following file access
Detection Strategies
- Review SysReptor audit logs for file upload events, focusing on filenames and content types not typically used in report evidence
- Inspect web proxy or browser telemetry for script executions originating from the SysReptor application domain
- Correlate account activity spikes with file access events to identify potential post-exploitation actions
Monitoring Recommendations
- Enable verbose logging on the SysReptor deployment and forward events to a central SIEM for retention and correlation
- Monitor authentication anomalies for accounts that recently accessed uploaded attachments
- Alert on new or modified files uploaded by accounts with low historical activity or recently created accounts
How to Mitigate CVE-2025-66561
Immediate Actions Required
- Upgrade all SysReptor instances to version 2025.102 or later without delay
- Audit user upload activity in versions prior to 2025.102 for suspicious JavaScript, HTML, or SVG files
- Rotate session tokens and API keys for users who may have accessed malicious uploads
- Review user permissions and remove upload rights from accounts that do not require them
Patch Information
Syslifters released a fix in SysReptor 2025.102. Upgrade instructions and release details are available in the GitHub Security Advisory GHSA-64vw-v5c4-mgvm. Self-hosted deployments should follow the standard upgrade procedure documented by the vendor.
Workarounds
- Restrict upload permissions to trusted users only until the patch is applied
- Deploy a reverse proxy rule to force a Content-Disposition: attachment header on downloaded files, preventing inline browser execution
- Enforce a strict Content Security Policy (CSP) at the reverse proxy layer to block inline script execution from the application origin
# Example nginx configuration to force attachment downloads and add CSP
location /api/v1/*/files/ {
add_header Content-Disposition "attachment" always;
add_header Content-Security-Policy "default-src 'none'; sandbox;" always;
add_header X-Content-Type-Options "nosniff" always;
proxy_pass http://sysreptor_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
