A new security vulnerability has been discovered in Bitwarden, the popular password management platform. The flaw, which affects versions up to v2.25.1, is tracked as CVE-2025-5138 and allows malicious actors to perform cross-site scripting (XSS) via malicious PDF files uploaded to the platform's file handling system.

Where is the problem located?
The vulnerability stems from a flaw in Bitwarden's Resources upload feature – specifically the PDF File Handler component. The application fails to properly validate user-controllable input before placing it in web page output, allowing the insertion and execution of potentially malicious code.
See also: Bitwarden makes it harder to hack passwords without MFA
The attack scenario is simple: the attacker uploads a PDF containing JavaScript code. When the end user opens the file in a browser (specifically via Google Chrome), the code is executed within the Bitwarden domain, opening the door for credential theft, session hijacking , and other unauthorized actions.
Proof of Concept and technical details
The exploitation process is quite simple. Attackers first access the Bitwarden web interface and navigate to the project creation section. After creating a new project, they use the file upload feature to deploy a malicious PDF containing embedded XSS payloads.
See also: What are use-after-free vulnerabilities and how to protect yourself
The vulnerability is particularly concerning because it allows remote exploitation without requiring authentication for certain items.
Security researchers published a proof-of-concept demonstration, making the exploit publicly available and increasing the risk of widespread exploitation.
See also: NETGEAR router vulnerability allows administrator access

Protection and treatment
Experts recommend immediately upgrading Bitwarden to a version newer than 2.25.1.
Suggested actions include:
- Integrate Content Security Policy (CSP) headers
- Enhanced input validation in file upload functionality
- Avoiding direct opening of PDF files in Bitwarden vaults
- Avoid opening suspicious attachments in browser tabs or windows
- Implementing sandboxing for content preview
The new vulnerability in Bitwarden reminds once again the need for constant vigilance, regular software updates, and the implementation of multi-layered security measures in applications that manage sensitive data such as passwords.
Source: gbhackers.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
