High8.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:H/SA:H

PT-2025-139: Stored XSS in Foundry Virtual Tabletop

Error type:

  • CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:H/SA:H
  • Severity (CVSSv4.0): 8.4 (High)

Description:

The vulnerability was identified in Foundry Virtual Tabletop, versions 13.350.

The discovered vulnerability allows an attacker to embed malicious JavaScript into the client‑side rendering pipeline of Foundry Virtual Tabletop (FVT) by exploiting unsafe handling of user‑controlled input. When the application generates HTML or dynamic UI components, it inserts the received data without proper sanitization or encoding, enabling the attacker to execute arbitrary scripts in the victim’s browser context.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 12.11.2025

Recommendations:

  • Update to version 13.351 or higher

Additional information: Security advisory

Researcher: Oleg Surnin (Positive Technologies)

Vendor:

Foundry Gaming, LLC.

Vulnerable product:

Foundry Virtual Tabletop

Vulnerable versions:

13.350