CVE-2025-12758
Validator Project Validator ≤ 13.15.22
Raw vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2025-12758 is a high-severity Incomplete Filtering of One or More Instances of Special Elements (CWE-792) vulnerability in Validator Project Validator. Its CVSS base score is 7.7 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Content Injection (T1659); ranked at the 41th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-15 (Information Output Filtering) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-199795
Vulnerability Data
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which…
more
lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
SI-10 directly requires validation of inputs which structurally prevents incomplete special-element filtering from being introduced or exploitable.
Output filtering enforces correct encoding or escaping of data leaving the system.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require complete input filtering and validation to prevent this class of weakness.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure coding explicitly requires correct character encoding and output escaping to avoid CWE-172.
Security testing in development and acceptance can detect incomplete filtering but does not itself implement the fix.
Secure development lifecycle mandates input validation and sanitization that directly prevents incomplete filtering of special elements.
Application security requirements explicitly call for input validation rules that mitigate incomplete special-element filtering.
Secure architecture principles encourage defensive input handling but do not prescribe the specific filtering mechanism.
Data leakage prevention may catch some downstream effects of unfiltered data but does not address the root filtering weakness.