A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
Update Pilz/PASvisu to 1.14.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanXSS vulnerability in Pilz PASvisu and PMI v8xx affects Pilz/PASvisu (generic), Pilz/PMI v8xx (generic). Severity is high. A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Pilz/PASvisugeneric | >=0.0.0 <1.14.1 | 1.14.1 |
| Pilz/PMI v8xx |
A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
Update Pilz/PASvisu to 1.14.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanXSS vulnerability in Pilz PASvisu and PMI v8xx affects Pilz/PASvisu (generic), Pilz/PMI v8xx (generic). Severity is high. A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Pilz/PASvisugeneric | >=0.0.0 <1.14.1 | 1.14.1 |
| Pilz/PMI v8xx |
| 0.0.0 |
| Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 0.0.0 |
| Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard