CVE-2025-65516: Seafile Server

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an attacker can upload a crafted SVG file containing malicious JavaScript and share it using a public link. Opening the link triggers script execution in the victim's browser. This issue has been fixed in Seafile Community Edition 13.0.12.

Affected products

  • Seafile Seafile Server: before 13.0.12 (fixed in 13.0.12)

Published 2025-12-04. Last modified 2026-06-17.