---
id: CVE-2025-52654
title: HCL MyXalytics v6.6 is affected by an HTML Injection
summary: >-
  HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when
  untrusted input is included in the output without proper handling, potentially
  allowing unauthorized content injection and manipulation.
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-80
vendor: hcltech
product: dryice_myxalytics
affected:
  - dryice_myxalytics = 6.6
published: '2025-10-03'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52654'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124411
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06693
ingestedAt: '2026-10-08T22:11:53.775Z'
---

## Overview

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

## Affected

- `dryice_myxalytics = 6.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
