CVE-2025-22249: VMware Aria Automation
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
Affected products
- VMware Aria Automation: version 8.18.0 only; version 8.18.1 only
- VMware Cloud Foundation: from 4.0, up to and including 5.2.1
- VMware Telco Cloud Platform: from 5.0, up to and including 5.0.1
Published 2025-05-13. Last modified 2026-06-17.