CVE-2025-64744 LOW

CVE-2025-64744: OpenObserve Vulnerable to HTML Injection in Organization Invitation Emails

Vendor Openobserve
Product openobserve
Weakness CWE-79 · XSS
Published November 13, 2025
Last update November 13, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML in the name, the markup is rendered inside the invitation email. This indicates that user-controlled input is inserted into the email template without proper HTML escaping. As of time of publication, no patched versions are available.

Key dates

02Disclosure timeline

November 13, 2025 CVE published
November 13, 2025 Record updated