CVE-2025-48050
Published May 15, 2025
·Updated
image-size is vulnerable to a Denial-of-Service vulnerability when processing specially crafted images.
Affected Software
4 affected componentsFixes available
DOMPurify DOMPurify<3.2.5
IBM Business Automation Insights<=25.0.0
IBM Business Automation Insights<=24.0.1
IBM Business Automation Insights<=24.0.0
Event History
May 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48050?
CVE-2025-48050 is a moderate severity vulnerability due to improper pathname handling in DOMPurify.
2
How do I fix CVE-2025-48050?
To fix CVE-2025-48050, upgrade to DOMPurify version 3.2.5 or later where the issue is resolved.
3
What are the potential impacts of CVE-2025-48050?
The potential impacts of CVE-2025-48050 include unauthorized access to sensitive file paths and potential execution of unintended scripts.
4
Which versions of DOMPurify are affected by CVE-2025-48050?
CVE-2025-48050 affects DOMPurify versions before 3.2.5.
5
Is there a workaround for CVE-2025-48050 if I cannot upgrade?
A temporary workaround for CVE-2025-48050 includes validating user input to ensure pathnames remain within the expected directory.