Skip to main content

CVE-2025-8191: Macrozheng Mall XSS Vulnerability

CVE-2025-8191 is a cross-site scripting flaw in Macrozheng Mall affecting Swagger UI that allows remote attackers to inject malicious scripts. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-8191 Overview

CVE-2025-8191 is a Cross-Site Scripting (XSS) vulnerability affecting macrozheng mall versions up to 1.0.3. The flaw resides in the bundled Swagger UI component, specifically in /swagger-ui/index.html. Attackers manipulate the configUrl query parameter to inject script content that executes in the victim's browser context. The vulnerability is classified under [CWE-79] and requires user interaction to trigger. Public disclosure occurred via VulDB and the Zast AI vulnerability reports repository. The vendor removed the associated GitHub issue and did not respond to email disclosure attempts.

Critical Impact

Remote attackers can execute arbitrary JavaScript in an authenticated user's browser session, potentially enabling session data theft, phishing overlays, or unauthorized actions within the mall administration interface.

Affected Products

  • macrozheng mall versions up to and including 1.0.3
  • The bundled Swagger UI component in /swagger-ui/index.html
  • Deployments exposing Swagger UI endpoints to untrusted networks

Discovery Timeline

  • 2025-07-26 - CVE-2025-8191 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8191

Vulnerability Analysis

The vulnerability is a DOM-based Cross-Site Scripting flaw in the Swagger UI shipped with macrozheng mall. Swagger UI accepts a configUrl query parameter that specifies the URL of a remote OpenAPI configuration document. When the front-end code processes an attacker-controlled configUrl value without proper validation, injected payloads are reflected into the DOM and executed. An attacker crafts a URL such as /swagger-ui/index.html?configUrl=<payload> and delivers it to a target user through phishing, chat, or a malicious link. Successful exploitation runs JavaScript under the origin of the mall application. This allows theft of session tokens stored in accessible browser storage, manipulation of on-page content, or forced administrative API calls if the victim is authenticated.

Root Cause

The root cause is missing input validation and sanitization of the configUrl parameter within Swagger UI's client-side logic. The parameter is treated as trusted and used to load configuration resources without an allowlist of acceptable origins. This maps to [CWE-79] Improper Neutralization of Input During Web Page Generation.

Attack Vector

Exploitation occurs over the network and requires user interaction. The attacker must convince a victim to click a crafted link pointing at the vulnerable Swagger UI endpoint. Privileges required are limited, since Swagger UI is often reachable by any authenticated developer or administrator. The exploit was disclosed publicly and is available through Exploit-DB references linked from VulDB.

No verified proof-of-concept code is reproduced here. Technical details are documented in the Zast AI DOM XSS Report and VulDB Vulnerability Details #317604.

Detection Methods for CVE-2025-8191

Indicators of Compromise

  • HTTP requests to /swagger-ui/index.html containing a configUrl parameter pointing to an external or unexpected domain
  • Web server access logs showing URL-encoded <script>, javascript:, or data: payloads in the configUrl query string
  • Browser referer chains where users arrived at /swagger-ui/index.html from external chat, email, or social media links

Detection Strategies

  • Deploy web application firewall (WAF) rules that inspect the configUrl parameter for non-allowlisted hosts and script-like payloads
  • Enable Content Security Policy (CSP) violation reporting to capture blocked script execution attempts on Swagger UI pages
  • Correlate anomalous outbound requests from browsers loading Swagger UI with unexpected configUrl values in proxy logs

Monitoring Recommendations

  • Alert on any external access to /swagger-ui/* paths on production mall deployments, since Swagger UI should not be internet-exposed
  • Monitor administrator and developer sessions for unusual API activity following visits to Swagger UI URLs
  • Track browser telemetry for JavaScript errors and CSP violations originating from the Swagger UI origin

How to Mitigate CVE-2025-8191

Immediate Actions Required

  • Restrict access to /swagger-ui/index.html and related Swagger endpoints so they are unreachable from untrusted networks or the public internet
  • Disable Swagger UI entirely in production builds of macrozheng mall until a vendor patch is available
  • Implement a strict Content Security Policy that blocks inline script execution and restricts script sources on any host serving Swagger UI

Patch Information

At the time of NVD publication no vendor patch is available. The vendor removed the GitHub Issue #919 tracking this vulnerability and did not respond to disclosure emails. Operators should monitor the upstream macrozheng mall repository for future releases addressing the Swagger UI configUrl handling. Additional references are catalogued in VulDB #317604.

Workarounds

  • Remove or comment out the Swagger UI dependency and routes in the mall application configuration before deploying to production environments
  • Place Swagger UI behind an authenticated reverse proxy that strips the configUrl query parameter from all incoming requests
  • Upgrade the bundled Swagger UI library to a current release that validates the configUrl parameter against an allowlist of trusted origins
  • Educate administrators and developers to avoid clicking Swagger UI links received from external sources
bash
# Example nginx snippet to strip configUrl and restrict access to internal networks
location /swagger-ui/ {
    allow 10.0.0.0/8;
    deny all;
    if ($arg_configUrl) {
        return 400;
    }
    proxy_pass http://mall-backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.