Tools AI-Found Vulnerability Register aifv-0046
Register entry
PAN-OS GlobalProtect reflected cross-site scripting, found by XBOW
- CVE
- CVE-2025-0133
- Project
- Palo Alto Networks PAN-OS
- Component
- GlobalProtect gateway and portal
- Finder
- XBOW
- Autonomy
- autonomous pentester with human review before submission
- Evidence tier
- Credits array names the finder
- Assigner
- palo_alto
- Severity
- 2.7 Low (CVSS 4.0)
- Bounty
- HackerOne; amount unpublished
- Confidence
- CONFIRMED
What happened
A reflected cross-site scripting flaw in the GlobalProtect gateway and portal, assigned by Palo Alto Networks with XBOW named as finder in the credits array. The record scores it 1.2 and 2.7 Low on CVSS 4.0, against the 2.0 and 5.5 in circulation.
Credit as recorded: finder: "XBOW". Date basis: datePublic.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Palo Alto Networks security advisorysecurity.paloaltonetworks.com/CVE-2025-0133
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026