CVE-2024-25677

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minbrowser:min:1.29.0:*:*:*:*:*:*:*

History

16 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - Third Party Advisory () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - Third Party Advisory

15 Feb 2024, 19:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:minbrowser:min:1.29.0:*:*:*:*:*:*:*
CWE NVD-CWE-Other
First Time Minbrowser
Minbrowser min
References () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - Third Party Advisory

09 Feb 2024, 14:26

Type Values Removed Values Added
Summary
  • (es) En Min anterior a 1.31.0, los archivos locales no se tratan correctamente como orígenes de seguridad únicos, lo que les permite solicitar incorrectamente recursos de orígenes cruzados. Por ejemplo, un archivo local puede solicitar otros archivos locales a través de un documento XML.

09 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-09 09:15

Updated : 2025-06-16 19:15


NVD link : CVE-2024-25677

Mitre link : CVE-2024-25677

CVE.ORG link : CVE-2024-25677


JSON object : View

Products Affected

minbrowser

  • min
CWE
NVD-CWE-Other CWE-284

Improper Access Control