swish-prolog cve# CVE-2025-63848
swish-prolog cve
Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.
---
# Impact
One click Account takeover.
---
# Mitigation
Upgrade to the latest version to mitigate the ATO.
https://github.com/SWI-Prolog/swish/commit/4fb6acb97bedf993ec406a2ef324eeb2a16c49e3
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view