CVE-2025-22249: VMware Aria Automation

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

Affected products

  • VMware Aria Automation: version 8.18.0 only; version 8.18.1 only
  • VMware Cloud Foundation: from 4.0, up to and including 5.2.1
  • VMware Telco Cloud Platform: from 5.0, up to and including 5.0.1

Published 2025-05-13. Last modified 2026-06-17.