Swagger UI versions 3.14.1 through 3.37.x are vulnerable to DOM-based Cross-Site Scripting (XSS) attacks. The vulnerability occurs when processing malicious configuration URLs that contain XSS payloads in the Swagger specification. An attacker can craft a malicious configUrl parameter that, when processed by Swagger UI, executes arbitrary JavaScript code in the victim's browser context.
id: CVE-2025-8191
info:
name: Swagger UI >=3.14.1 < 3.38.0 - DOM Based Cross-Site Scripting
aut
...