CVE-2025-67724 | tornadoweb tornado up to 6.5.2 RequestHandler.set_status Reason cross site scripting (GHSA-pr2v-jx2c-wg9f)
A vulnerability was found in tornadoweb tornado up to 6.5.2. It has been rated as problematic. This affects the function RequestHandler.set_status. This manipulation of the argument Reason causes cross site scripting.
This vulnerability is handled as CVE-2025-67724. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.