CVE-2025-27155

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.
Configurations

No configuration.

History

04 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 17:15

Updated : 2025-03-04 17:15


NVD link : CVE-2025-27155

Mitre link : CVE-2025-27155

CVE.ORG link : CVE-2025-27155


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)