CVE-2025-13488: Sonatype Nexus Repository

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.

Affected products

  • Sonatype Nexus Repository: from 3.83.0, up to and including 3.86.2

Published 2025-12-04. Last modified 2026-06-17.