# Bee SDK patched for stored XSS flaw

Published: 2026-03-18 · Severity: medium
Canonical: https://vorant.io/reports/b20eba07-5fc8-50c4-9e12-d3dd25ce8e87/bee-sdk-patched-for-stored-xss-flaw

> A stored XSS vulnerability in beefree.io SDK's email builder allows HTML/JS injection in social media icon URLs, patched in version 3.47.0.

CERT Polska coordinated the disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Bee Content Design Befree SDK software. The flaw exists in the email builder functionality, specifically in the Social Media icon URL parameter, where an attacker can inject arbitrary HTML and JavaScript into templates. When a user visits the preview page, the malicious code is rendered and potentially executed.

The vulnerability's impact is somewhat mitigated by beefree's Content Security Policy, which prevents certain payloads from executing successfully. However, the stored nature of the XSS means malicious content persists in templates and could affect multiple users who access the preview functionality.

The vendor has addressed the issue in version 3.47.0 of the Befree SDK. The vulnerability was responsibly disclosed by security researcher Michał Błaszczak and coordinated through CERT Polska's vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2025-12518

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b20eba07-5fc8-50c4-9e12-d3dd25ce8e87/bee-sdk-patched-for-stored-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
