CVE-2025-3019: Knime Business Hub

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data. The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.3 or later * 1.12.4 or later

Affected products

  • Knime Business Hub: before 1.12.4 (fixed in 1.12.4); from 1.13.0, before 1.13.3 (fixed in 1.13.3)

Published 2025-03-31. Last modified 2026-06-17.