CVE-2025-7062
Deferred Deferred - Pending Action

Stored XSS in H5P Node.js Library

Vulnerability report for CVE-2025-7062, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-22

Assigner: SCHUTZWERK

Description

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-22
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lumi_education_ug h5p_nodejs_library to 10.0.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the H5P module h5p-nodejs-library by Lumi Education UG affecting versions up to 10.0.4. Users can upload H5P content containing malicious JavaScript, which executes in the browsers of other users viewing the content. The issue occurs because SVG files with embedded scripts are not properly sanitized, allowing attackers to bypass restrictions and execute harmful code.

Detection Guidance

To detect this vulnerability, inspect uploaded H5P content for SVG or XML files with embedded JavaScript. Check server logs for unusual script execution patterns. Use tools like grep to search for script tags in uploaded files. Example command: grep -r '<script>' /path/to/h5p/content. Also review browser console logs for unexpected script executions when viewing H5P content.

Impact Analysis

The vulnerability can lead to account hijacking, phishing attacks, session tracking, and potential privilege escalation if an admin user is targeted. Attackers can steal session cookies, display fake alerts, or perform unauthorized actions on behalf of users. Malicious scripts may also track user activity or redirect to malicious websites.

Compliance Impact

This vulnerability could violate GDPR by exposing user data through session hijacking or unauthorized access. For HIPAA, it may compromise protected health information if attackers gain access to sensitive data. Non-compliance risks include legal penalties, reputational damage, and loss of trust due to inadequate security measures.

Mitigation Strategies

Immediately enable SVG sanitization using DOMPurify. Validate uploaded files based on content rather than just filename extensions. Block SVG and XML uploads unless explicitly required. Update to the latest version of h5p-nodejs-library if available. Monitor for suspicious activity in user sessions and content uploads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-7062. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart