# Security Release for issue #14363

**URL:** https://discuss.tryton.org/t/security-release-for-issue-14363/8951
**Category:** News
**Tags:** security
**Created:** [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14363/8951 "2025-11-21T15:00:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14363/8951/1 "2025-11-21T15:00:48Z")

</div>

[Abdulfatah Abdillahi](https://foss.heptapod.net/Abdul123) has found that [sao](https://www.npmjs.com/package/tryton-sao) [does not escape the completion values](https://bugs.tryton.org/14363). The content of completion is generally the record name which may be edited in many ways depending on the model. The content may include some JavaScript which is executed in the same context as sao which gives access to sensitive data such as the session.

## Impact

[CVSS v3.0 Base Score: 7.3](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:H/RL:O/RC:C/CR:H/IR:H/MAV:N/MAC:L/MPR:L/MUI:R/MS:U/MC:H/MI:H/MA:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: High
- Integrity: High
- Availability: None

## Workaround

There is no general workaround.

## Resolution

All affected users should upgrade `sao` to the latest version.

Affected versions per series:

- `sao`:
  - 7.6: \<= 7.6.10
  - 7.4: \<= 7.4.20
  - 7.0: \<= 7.0.39
  - 6.0: \<= 6.0.68

Non affected versions per series:

- `sao`:
  - 7.6: \>= 7.6.11
  - 7.4: \>= 7.4.21
  - 7.0: \>= 7.0.40
  - 6.0: \>= 6.0.69

## Reference

- [Stored XSS Vulnerability Found in Party Field Leading to Arbitrary JavaScript Execution (#14363) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/14363)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![yangoon](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/y/67e7ee/32.png) [@yangoon](https://discuss.tryton.org/u/yangoon)
#### Post date: [December 1, 2025, 9:24pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14363/8951/2 "2025-12-01T21:24:42Z")

</div>

CVE-2025-66421 was assigned to this issue (s.a. [https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121242)233)

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [December 21, 2025, 3:01pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14363/8951/3 "2025-12-21T15:01:22Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
