CVE-2025-6508
Received Received - Intake

Swagger UI API Definition Override in WSO2 API Manager

Vulnerability report for CVE-2025-6508, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API definitions. This could lead to the exposure of sensitive information or the initiation of unintended requests to backend services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Swagger UI Try-out console in the API Publisher documentation allows loading an external Swagger API definition URL, which replaces the existing API definitions in the Publisher portal. Attackers can exploit this to trick users into interacting with malicious API definitions, potentially exposing sensitive data or triggering unintended backend requests.

Detection Guidance

This vulnerability involves the Swagger UI Try-out console in the API Publisher documentation loading external Swagger API definitions. To detect it, inspect network traffic for unexpected API definition loads or unauthorized modifications to API endpoints. Check server logs for unusual requests to the Swagger UI console or API Publisher portal.

Impact Analysis

This vulnerability could lead to sensitive information exposure or unauthorized actions on backend services if users interact with the malicious API definitions. It may also result in data breaches or service disruptions depending on the API's functionality.

Compliance Impact

This vulnerability could lead to exposure of sensitive information or unintended requests to backend services, which may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy). Unauthorized access or data leaks could result in regulatory penalties or breaches of confidentiality.

Mitigation Strategies

Disable the Swagger UI Try-out console in the API Publisher documentation to prevent external API definition URLs from being loaded. Review API definitions for unauthorized changes and restrict access to sensitive backend services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-6508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart