A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 28 Oct 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Chatwoot
Chatwoot chatwoot
Vendors & Products Chatwoot
Chatwoot chatwoot

Mon, 27 Oct 2025 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Title chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation
Weaknesses CWE-345
CWE-346
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-27T07:32:07.544Z

Updated: 2025-10-27T18:25:56.142Z

Reserved: 2025-10-26T05:12:01.062Z

Link: CVE-2025-12245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T08:15:36.950

Modified: 2025-10-28T02:15:11.223

Link: CVE-2025-12245

cve-icon Redhat

No data.