CVE-2026-25156Disclosure(hotcrp / hotcrp)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hotcrp hotcrp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be rendered in the user’s browser rather than downloaded. (The intended behavior was for only `text/plain`, `application/pdf`, `image/gif`, `image/jpeg`, and `image/png` to be delivered inline, though adding `save=0` to the document URL could request inline delivery for any document.) This made users who clicked a document link vulnerable to cross-site scripting attacks. An uploaded HTML or SVG document would run in the viewer’s browser with access to their HotCRP credentials, and Javascript in that document could eventually make arbitrary calls to HotCRP’s API. Malicious documents could be uploaded to submission fields with “file upload” or “attachment” type, or as attachments to comments. PDF upload fields were not vulnerable. A search of documents uploaded to hotcrp.com found no evidence of exploitation. The vulnerability was introduced in commit aa20ef288828b04550950cf67c831af8a525f508 (11 October 2025), present in development versions and v3.2, and fixed in commit 8933e86c9f384b356dc4c6e9e2814dee1074b323 and v3.2.1. Additionally, c3d88a7e18d52119c65df31c2cc994edd2beccc5 and v3.2.1 remove support for `save=0`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hotcrp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
hotcrp

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-30: 1Mentions · 2026-02-01: 1Patch / Workaround · 2026-02-01: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 101-3002-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-301
Disclosure1
2026-02-011
Patch1
Full discourse2 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A stored XSS flaw (CVE-2026-25156) in HotCRP via comment attachments enables script injection. System administrators should review and patch their deployments. #HotCRP #XSS #infosec https://www.pulsepatch.io/posts/cve-2026-25156-hotcrp-stored-xss

    Post summary

    HotCRP suffers from a stored XSS vulnerability (CVE‑2026‑25156) that permits script injection through comment attachments; administrators are urged to review and apply patches.

    00000220
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25156 HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing… https://www.cve.org/CVERecord?id=CVE-2026-25156

    Post summary

    The text announces CVE‑2026‑25156, indicating that HotCRP versions from October 2025 to January 2026 delivered documents with inline Content‑Disposition, implying a potential vulnerability.

    00000176
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphotcrphotcrp3.2--

Explore more