CVE-2024-25677: Minbrowser Min

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.

Affected products

Published 2024-02-09. Last modified 2026-06-17.