---
id: CVE-2025-67634
title: >-
  The CISA Software Acquisition Guide Supplier Response Web Tool before
  2025-12-11 was vulnerable to cross-site scripting via text fields
summary: >-
  The CISA Software Acquisition Guide Supplier Response Web Tool before
  2025-12-11 was vulnerable to cross-site scripting via text fields. If an
  attacker could convince a user to import a specially-crafted JSON file, the
  Tool would load Ja…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: cisa
product: software_acquisition_guide
affected:
  - software_acquisition_guide < 2025-12-11
patched:
  - software_acquisition_guide 2025-12-11
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67634'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-345-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cisa.gov/software-acquisition-guide/tool'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-67634'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.0019
epssPercentile: 0.07923
ingestedAt: '2026-10-07T20:46:46.921Z'
---

## Overview

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').

## Affected

- `software_acquisition_guide < 2025-12-11`

## Remediation

Upgrade past the affected range:

- `software_acquisition_guide 2025-12-11`
