CVE-2025-27155

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Pinecone es un conjunto de protocolos de enrutamiento superpuestos experimentales que constituye la base de las demostraciones actuales de P2P Matrix. El simulador de Pinecone (pineconesim) incluido en Pinecone hasta el commit ea4c337 es vulnerable a cross site scripting almacenado. El almacenamiento del payload no es permanente y se borrarĂ¡ al reiniciar pineconesim.

04 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-27155

Mitre link : CVE-2025-27155

CVE.ORG link : CVE-2025-27155


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)