CVE-2025-8191 Overview
CVE-2025-8191 is a Cross-Site Scripting (XSS) vulnerability affecting macrozheng mall versions up to 1.0.3. The flaw resides in the bundled Swagger UI component, specifically in /swagger-ui/index.html. Attackers manipulate the configUrl query parameter to inject script content that executes in the victim's browser context. The vulnerability is classified under [CWE-79] and requires user interaction to trigger. Public disclosure occurred via VulDB and the Zast AI vulnerability reports repository. The vendor removed the associated GitHub issue and did not respond to email disclosure attempts.
Critical Impact
Remote attackers can execute arbitrary JavaScript in an authenticated user's browser session, potentially enabling session data theft, phishing overlays, or unauthorized actions within the mall administration interface.
Affected Products
- macrozheng mall versions up to and including 1.0.3
- The bundled Swagger UI component in /swagger-ui/index.html
- Deployments exposing Swagger UI endpoints to untrusted networks
Discovery Timeline
- 2025-07-26 - CVE-2025-8191 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8191
Vulnerability Analysis
The vulnerability is a DOM-based Cross-Site Scripting flaw in the Swagger UI shipped with macrozheng mall. Swagger UI accepts a configUrl query parameter that specifies the URL of a remote OpenAPI configuration document. When the front-end code processes an attacker-controlled configUrl value without proper validation, injected payloads are reflected into the DOM and executed. An attacker crafts a URL such as /swagger-ui/index.html?configUrl=<payload> and delivers it to a target user through phishing, chat, or a malicious link. Successful exploitation runs JavaScript under the origin of the mall application. This allows theft of session tokens stored in accessible browser storage, manipulation of on-page content, or forced administrative API calls if the victim is authenticated.
Root Cause
The root cause is missing input validation and sanitization of the configUrl parameter within Swagger UI's client-side logic. The parameter is treated as trusted and used to load configuration resources without an allowlist of acceptable origins. This maps to [CWE-79] Improper Neutralization of Input During Web Page Generation.
Attack Vector
Exploitation occurs over the network and requires user interaction. The attacker must convince a victim to click a crafted link pointing at the vulnerable Swagger UI endpoint. Privileges required are limited, since Swagger UI is often reachable by any authenticated developer or administrator. The exploit was disclosed publicly and is available through Exploit-DB references linked from VulDB.
No verified proof-of-concept code is reproduced here. Technical details are documented in the Zast AI DOM XSS Report and VulDB Vulnerability Details #317604.
Detection Methods for CVE-2025-8191
Indicators of Compromise
- HTTP requests to /swagger-ui/index.html containing a configUrl parameter pointing to an external or unexpected domain
- Web server access logs showing URL-encoded <script>, javascript:, or data: payloads in the configUrl query string
- Browser referer chains where users arrived at /swagger-ui/index.html from external chat, email, or social media links
Detection Strategies
- Deploy web application firewall (WAF) rules that inspect the configUrl parameter for non-allowlisted hosts and script-like payloads
- Enable Content Security Policy (CSP) violation reporting to capture blocked script execution attempts on Swagger UI pages
- Correlate anomalous outbound requests from browsers loading Swagger UI with unexpected configUrl values in proxy logs
Monitoring Recommendations
- Alert on any external access to /swagger-ui/* paths on production mall deployments, since Swagger UI should not be internet-exposed
- Monitor administrator and developer sessions for unusual API activity following visits to Swagger UI URLs
- Track browser telemetry for JavaScript errors and CSP violations originating from the Swagger UI origin
How to Mitigate CVE-2025-8191
Immediate Actions Required
- Restrict access to /swagger-ui/index.html and related Swagger endpoints so they are unreachable from untrusted networks or the public internet
- Disable Swagger UI entirely in production builds of macrozheng mall until a vendor patch is available
- Implement a strict Content Security Policy that blocks inline script execution and restricts script sources on any host serving Swagger UI
Patch Information
At the time of NVD publication no vendor patch is available. The vendor removed the GitHub Issue #919 tracking this vulnerability and did not respond to disclosure emails. Operators should monitor the upstream macrozheng mall repository for future releases addressing the Swagger UI configUrl handling. Additional references are catalogued in VulDB #317604.
Workarounds
- Remove or comment out the Swagger UI dependency and routes in the mall application configuration before deploying to production environments
- Place Swagger UI behind an authenticated reverse proxy that strips the configUrl query parameter from all incoming requests
- Upgrade the bundled Swagger UI library to a current release that validates the configUrl parameter against an allowlist of trusted origins
- Educate administrators and developers to avoid clicking Swagger UI links received from external sources
# Example nginx snippet to strip configUrl and restrict access to internal networks
location /swagger-ui/ {
allow 10.0.0.0/8;
deny all;
if ($arg_configUrl) {
return 400;
}
proxy_pass http://mall-backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.