Bee SDK patched for stored XSS flaw
A stored XSS vulnerability in beefree.io SDK's email builder allows HTML/JS injection in social media icon URLs, patched in version 3.47.0.
CERT Polska coordinated the disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Bee Content Design Befree SDK software. The flaw exists in the email builder functionality, specifically in the Social Media icon URL parameter, where an attacker can inject arbitrary HTML and JavaScript into templates. When a user visits the preview page, the malicious code is rendered and potentially executed.
The vulnerability's impact is somewhat mitigated by beefree's Content Security Policy, which prevents certain payloads from executing successfully. However, the stored nature of the XSS means malicious content persists in templates and could affect multiple users who access the preview functionality.
The vendor has addressed the issue in version 3.47.0 of the Befree SDK. The vulnerability was responsibly disclosed by security researcher Michał Błaszczak and coordinated through CERT Polska's vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free