CVE-2025-63317: Doist Todoist
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user opens the attachment from a task/comment.
Affected products
- Doist Todoist: version 8486 only
Published 2025-12-01. Last modified 2026-06-17.