CVE-2025-67634 MEDIUM

CVE-2025-67634: Software Acquisition Guide Supplier Response Web Tool XSS

Vendor Cisa
Product Software Acquisition Guide Tool
Weakness CWE-79 · XSS
Published December 12, 2025
Last update January 8, 2026

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').

Key dates

02Disclosure timeline

December 12, 2025 CVE published
January 8, 2026 Record updated