CVE-2025-56795

critical

Description

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

References

https://github.com/mealie-recipes/mealie/pull/5754

https://github.com/mealie-recipes/mealie/issues/5677

https://github.com/B1tBreaker/CVE-2025-56795

Details

Source: Mitre, NVD

Published: 2025-09-29

Updated: 2025-10-16

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00029