Broadcom has released an urgent security advisory for a high-severity DOM-based Cross-Site Scripting (XSS) vulnerability affecting VMware Aria automation products.
The vulnerability, tracked as CVE-2025-22249, could allow attackers to steal access tokens from logged-in users, potentially leading to unauthorized system access and account compromise.
The security flaw, assigned a CVSSv3 base score of 8.2, was disclosed on May 12, 2025, in the security advisory VMSA-2025-0008. Researchers have identified that the vulnerability exists in the Document Object Model (DOM) implementation of VMware Aria automation, allowing malicious actors to execute crafted JavaScript code in victims’ browsers.
“A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL,” states the advisory from Broadcom.
The attack vector relies on social engineering techniques to convince users to interact with specially crafted URLs containing malicious payloads.
The exploitation doesn’t require authentication to the system, but it does require user interaction, as victims need to click on the malicious link while logged into the VMware Aria automation platform. Once executed, the injected code can capture authentication tokens and transmit them to attacker-controlled systems.
Affected Products
Several VMware products are impacted by this vulnerability, and Broadcom has issued patches to resolve the issue.
| Product | Affected Versions | Fixed Version / Patch |
|---|---|---|
| VMware Aria Automation | 8.18.x and earlier | 8.18.1 patch 2 |
| VMware Cloud Foundation | 4.x, 5.x | See KB394224 |
| VMware Telco Cloud Platform | 5.x | 8.18.1 patch 2 |
This vulnerability adds to recent security concerns for VMware products, following the critical VMware ESXi vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) disclosed earlier this year that were actively exploited in the wild.
Security experts recommend that organizations implement the patches immediately, as there are no workarounds available for this vulnerability.
While no public proof-of-concept or active exploitation has been reported yet, security researchers warn that DOM-based XSS vulnerabilities are relatively straightforward to exploit once discovered.
While applying the official patches, organizations are advised to take additional precautions:
- Implement web application firewalls with XSS protection capabilities
- Train users to recognize suspicious links and phishing attempts
- Enable multi-factor authentication where possible
- Regularly audit system access logs for unauthorized activity
Security researcher Bartosz Reginiak privately reported the vulnerability to VMware, demonstrating the ongoing importance of responsible vulnerability disclosure in protecting enterprise systems.
This latest VMware vulnerability highlights organizations’ continuing challenges in securing complex enterprise software ecosystems. Timely patching remains the most effective defense against such vulnerabilities, especially when no workarounds exist.
Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar
