CVE-2025-40900
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious report template. When the victim views or imports the report, the Angular template executes in their browser context, allowing the attacker to modify application data, or disrupt application availability. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-1336
- Published
- 2026-05-19
- Last modified
- 2026-08-11
Affected products
- Nozomi Networks Guardian
- Nozomi Networks CMC
Weakness type
Related vulnerabilities
- CVE-2025-34300 — Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
- CVE-2025-49136 — listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2025-66294 — Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
- CVE-2026-33897 — Incus vulnerable to arbitrary file read and write through pongo templates
- CVE-2025-53833 — LaRecipe is vulnerable to Server-Side Template Injection attacks
- CVE-2025-47916 — Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
- CVE-2025-46661 — IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the at