
CVE-2025-57543 Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI … https://www.cve.org/CVERecord?id=CVE-2025-57543
Post summary
The text announces an XSS vulnerability in NetBox 4.3.5’s comment field, allowing arbitrary HTML injection, without mentioning patches or exploitation status.

