---
id: CVE-2022-25507
aliases:
  - GHSA-gjh6-wvhq-h4qx
  - PYSEC-2026-639
title: Cross-site Scripting in FreeTAKServer-UI
summary: Cross-site Scripting in FreeTAKServer-UI
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: freetakserver-ui
product: freetakserver-ui
ecosystem: pip
affected:
  - freetakserver-ui <= 1.9.8
published: '2022-03-12'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:28.315043294Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-gjh6-wvhq-h4qx'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-25507'
  - url: 'https://github.com/FreeTAKTeam/UI/issues/28'
  - url: 'https://github.com/FreeTAKTeam/UI'
tags:
  - osv
  - pip
epss: 0.00491
epssPercentile: 0.3955
ingestedAt: '2026-07-08T18:25:49.730Z'
---

## Overview

FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.

## Affected packages

- `freetakserver-ui <= 1.9.8`

## Remediation

Refer to the advisory for the patched release.
