CVE-2018-25031 is a spoofing vulnerability in Swagger UI affecting version 4.1.2 and earlier, with reports indicating the issue may also persist in 4.1.3 and possibly later versions despite an initial claim of resolution. The flaw allows an attacker to craft a URL that causes Swagger UI to load and display a remote, attacker-controlled OpenAPI definition. By inducing a victim to open the crafted link, the attacker can present untrusted API documentation within the trusted Swagger UI interface, creating a misleading representation of API content and origin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a proof-of-concept (POC) exploit for CVE-2018-25031, a vulnerability in Swagger UI that allows HTML/JavaScript injection via user-supplied configuration files. The repository contains several YAML and JSON files (img.yaml, login.yaml, remote-login.yaml and their corresponding .json wrappers) that are designed to be loaded into Swagger UI using the 'configUrl' parameter. These files inject malicious HTML and JavaScript into the Swagger UI interface, demonstrating XSS attacks. Notably, the img.yaml file uses a 'javascript:' URI in the OAuth2 authorizationUrl and embeds HTML with event handlers (onload, onclick, onerror) to trigger JavaScript execution. The remote-login.yaml references an external domain (https://evil.com), which could be used for phishing or data exfiltration. The README provides instructions for using these payloads by supplying the configUrl parameter to a vulnerable Swagger UI instance. The repository is structured as a POC, with no executable code, but provides all necessary payloads to demonstrate the vulnerability.
This repository contains a collection of OpenAPI/Swagger specification files (in YAML and JSON formats) designed to exploit CVE-2018-25031, a DOMPurify XSS vulnerability. The files include a variety of payloads: - XSS vectors embedded in API documentation fields (e.g., <img src onerror=alert(1)>, <svg onload=alert(1)>, <a href="javascript:alert('XSS')">). - Phishing forms that post credentials to attacker-controlled endpoints (e.g., https://attackersite). - A Node.js reverse shell payload in rc.yaml, which attempts to connect to 18.210.137.174:4444. - Malicious endpoints and paths (e.g., /pwnd, /malformed_by_ras) to simulate vulnerable API routes. The repository is structured as a set of paired .json and .yaml files, each referencing a specific malicious OpenAPI/Swagger file. The main purpose is to provide proof-of-concept (POC) files for testing and demonstrating exploitation of the DOMPurify XSS vulnerability in systems that process or render OpenAPI/Swagger documentation. The payloads are primarily for browser-based attacks (XSS, phishing) and one network-based attack (reverse shell).
This repository contains proof-of-concept (POC) exploit files for CVE-2018-25031, targeting a DOM-based or reflected XSS vulnerability in API documentation viewers that process Swagger/OpenAPI files. The repository includes several YAML and JSON files: - 'domxss.yaml' and 'xss1.yaml' are Swagger/OpenAPI definitions crafted to include malicious JavaScript payloads in fields such as 'description', 'termsOfService', and 'contact'. These payloads use vectors like <img onerror=alert(document.domain) src> and javascript:alert(document.cookie) to trigger XSS when rendered by a vulnerable viewer. - 'poc.json' and 'xss.json' reference the malicious YAML files, likely for automated testing or demonstration purposes. - 'poc.yaml' is another OpenAPI file with a suspicious endpoint but does not contain a direct payload. The main attack vector is browser-based: if a user or system loads these Swagger/OpenAPI files in a documentation viewer that does not properly sanitize input, arbitrary JavaScript will execute. The repository does not contain executable code but provides weaponized data files for XSS exploitation. The only network endpoint present is a test domain (oastify.com) used as the API base path in 'domxss.yaml'. Overall, the repository is structured as a POC for demonstrating XSS via malicious API documentation files.
This repository provides a proof-of-concept (POC) exploit for CVE-2018-25031, a vulnerability in Swagger UI (before version 4.1.3) that allows remote attackers to conduct spoofing and XSS attacks by injecting malicious OpenAPI definitions via the 'url' or 'configUrl' parameters. The repository contains several crafted YAML and JSON files (test.yaml, xss.yaml, xss2.yaml, f.yaml, htmli.yaml, redirect.yaml, and their JSON wrappers) that include embedded HTML and JavaScript payloads for XSS, phishing, and redirection attacks. The README.md explains how to use these files by supplying their URLs to a vulnerable Swagger UI instance, either directly or via base64-encoded data URLs. The payloads demonstrate various attack scenarios, such as credential phishing forms, XSS alerts, cookie theft, and redirection to external sites. The repository is structured as a collection of malicious API definition files intended for use in browser-based attacks against Swagger UI endpoints, and does not contain executable code but rather data files for exploitation.
This repository provides a proof-of-concept (PoC) exploit for CVE-2018-25031, a vulnerability in Swagger UI before version 4.1.3 that allows remote attackers to conduct spoofing attacks by loading remote OpenAPI definitions. The exploit consists of several files: - `README.md` explains the vulnerability, provides PoC URLs, and references the CVE. - `DOMXSS.yaml` and `poc.yaml` are malicious OpenAPI definition files, with `DOMXSS.yaml` containing an embedded DOM-based XSS payload in the API documentation fields. - `poc.json` and `poc2.json` are configuration files that point to the malicious OpenAPI definitions. The main attack vector is browser-based: a victim is tricked into visiting a Swagger UI instance with a crafted URL (using the `configUrl` or `url` parameter) that loads a remote, attacker-controlled OpenAPI definition. This can result in spoofed API documentation or execution of malicious JavaScript (DOM XSS) in the context of the Swagger UI page. The repository does not contain executable code but provides all necessary files to demonstrate and reproduce the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.