VORANT. Threat Intelligence Sign in Get the full feed

Bee SDK patched for stored XSS flaw

medium vulnerability

A stored XSS vulnerability in beefree.io SDK's email builder allows HTML/JS injection in social media icon URLs, patched in version 3.47.0.

CERT Polska coordinated the disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Bee Content Design Befree SDK software. The flaw exists in the email builder functionality, specifically in the Social Media icon URL parameter, where an attacker can inject arbitrary HTML and JavaScript into templates. When a user visits the preview page, the malicious code is rendered and potentially executed.

The vulnerability's impact is somewhat mitigated by beefree's Content Security Policy, which prevents certain payloads from executing successfully. However, the stored nature of the XSS means malicious content persists in templates and could affect multiple users who access the preview functionality.

The vendor has addressed the issue in version 3.47.0 of the Befree SDK. The vulnerability was responsibly disclosed by security researcher Michał Błaszczak and coordinated through CERT Polska's vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2025-12518

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free