216.73.216.6

CVE-2025-69517

· Published 28/01/2026 16:16 · Modified 29/01/2026 18:16

Labels: CVE-2025-69517 2026-01-28CVE-2025-69517CWE-94[email protected]

Essential information

Published
28/01/2026 16:16
Modified
29/01/2026 18:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creation of a new agent via the POST /api/v3/newagent/ endpoint. The agent_id parameter accepts up to 255 characters and is improperly sanitized using DOMPurify.sanitize() with the html: true option enabled, which fails to adequately filter HTML input. The injected HTML is rendered in the Tactical RMM management panel when an administrator attempts to remove or shut down the affected agent, potentially leading to client-side attacks such as UI manipulation or phishing.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
amidaware / tactical rmm cpe:2.3:a:amidaware:tactical_rmm:<1.3.1:*:*:*:*:*:*:*

References