CVE-2025-58353: Marcelotessaro Promptcraft-Forge-Studio
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists such as r`eplace(/javascript:/gi, '')`. Because the package uses multi-character tokens and each replacement is applied only once, removing one occurrence can create a new dangerous token due to overlap. The “sanitized” value may still contain an executable payload when used in href/src (or injected into the DOM). There is currently no fix for this issue.
Affected products
- Marcelotessaro Promptcraft-Forge-Studio: from 0
Published 2025-09-04. Last modified 2026-06-17.