PatchSiren cyber security CVE debrief
CVE-2025-7062 Lumi Education UG CVE debrief
A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content. Defenders should prioritize verifying the version of `h5p-nodejs-library` in use and assessing the exposure of users who view H5P content. The scope of affected versions and potential impact require further verification.
- Vendor
- Lumi Education UG
- Product
- h5p-nodejs-library
- CVSS
- MEDIUM 5.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for maintaining and securing H5P content and users who view H5P content should be aware of this vulnerability and take steps to verify their exposure. Defenders should prioritize verifying the version of `h5p-nodejs-library` in use and assessing the exposure of users who view H5P content. The scope of affected versions and potential impact require further verification. Operators, platform administrators, vulnerability management teams
Why it matters
A stored cross-site scripting (XSS) vulnerability in the H5P module `h5p-nodejs-library` allows users to upload malicious JavaScript that is executed in the browsers of other users who view the affected H5P content. Defenders should prioritize verifying the version of `h5p-nodejs-library` in use and assessing the exposure of users who view H5P content. The scope of affected versions and potential impact require further verification.
- User browsers may execute malicious JavaScript when viewing affected H5P content
- Defenders should verify the version of `h5p-nodejs-library` in use and assess the exposure of users who view H5P content
- Defenders should consider upgrading to a patched version if available
Technical summary
The H5P module `h5p-nodejs-library` allows users to upload H5P content that contains malicious JavaScript, which is then executed in the browsers of other users who view the affected H5P content. Defenders should prioritize verifying the version of `h5p-nodejs-library` in use and assessing the exposure of users who view H5P content. The scope of affected versions and potential impact require further verification. Affected product deployments should be reviewed for exposure, and compensating controls should be considered.
Defensive priority
Defenders should prioritize verifying the version of `h5p-nodejs-library` in use and assessing the exposure of users who view H5P content.
Recommended defensive actions
- Verify the version of `h5p-nodejs-library` in use
- Assess the exposure of users who view H5P content
- Consider upgrading to a patched version if available
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but the scope of affected versions and potential impact require further verification. Defenders should verify the version of `h5p-nodejs-library` in use and assess the exposure of users who view H5P content. The CVE Program record and NVD entry provide source-provided CVE metadata and official vulnerability assessment. Additional verification is needed to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-7062 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-7062
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-7062 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-7062
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Lumieducation/H5P-Nodejs-library/releases/tag/v10.0.4
23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
-
Source reference
Unverified legacy reference
URL: https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-007/
23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.