CVE-2025-15095 | postmanlabs httpbin up to 0.6.1 core.py cross site scripting (Issue 735 / EUVD-2025-205412)
A vulnerability, which was classified as problematic, has been found in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-15095. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.