Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s Software Acquisition Guide: Supplier Response Web Tool had a cross-site scripting (XSS) flaw, tracked as CVE-2025-67634. The CVE says a user could trigger JavaScript in their own browser by importing a specially crafted JSON file and then clicking “Next.” CyberScoop reported that CISA patched the issue in December 2025; the agency’s CIO said there was no known exploitation.

What was the CISA secure-software tool vulnerability?

The affected resource was CISA’s hosted Software Acquisition Guide: Supplier Response Web Tool—not a downloadable package users can update themselves. The CVE record classifies the flaw as CWE-79, improper neutralization of input during web page generation, commonly called cross-site scripting or XSS.

CISA’s guide, published on August 1, 2024, is intended to help government acquisition teams assess suppliers’ security practices across the software lifecycle and make risk-informed purchasing decisions. The web tool adapts questions to earlier answers and lets users export and print a tailored summary for decision-makers. The irony is that a tool supporting secure software procurement was itself reported to have a web vulnerability; that does not establish that its questionnaire or procurement guidance was compromised. CISA’s guide and tool

How did the XSS flaw work?

The CVE describes a user-interaction-dependent sequence: a user imports a specially crafted JSON file, the tool loads JavaScript from it, and the script runs in that user’s browser after they click “Next” to submit the page. The record does not describe script execution simply from visiting the tool.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Import a specially crafted JSON file into the tool.
  2. Click “Next” to submit the page.
  3. The JavaScript loaded from the file executes in the user’s browser context.

That is the attack path documented by the CVE. Williams told CyberScoop that injected JavaScript could also be used to attack other users of the same page or deface the website. Those are his broader impact claims; they should not be confused with the CVE’s description of execution in the importing user’s browser. CISA and FBI’s September 17, 2024 alert describes XSS vulnerabilities as preventable and calls on technology manufacturers’ senior leaders to review past defects and plan prevention, but does not identify the specific coding error in this tool.

Was CISA’s tool patched, and when?

CyberScoop reported on January 15, 2026, that Jeff Williams, Contrast Security co-founder and CTO and a former OWASP leader, said he reported the flaw in September and that it was fixed in December. CISA CIO Robert Costello told the outlet that the agency addressed and patched the vulnerability. Separately, the CVE record says the tool was affected before December 11, 2025, and lists December 11, 2025, as unaffected. The CVE’s date boundary is not a technical patch-version number or a description of the remediation method.

Costello also said CISA identified process improvements for future vulnerability reports. Williams criticized the lapse, telling CyberScoop: “I thought it was a little hypocritical to be promoting secure software development and not do the most basic test you could possibly do.” That is Williams’s opinion, not an independent audit finding. CyberScoop’s January 15, 2026 report

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was the CISA vulnerability exploited?

Costello told CyberScoop that CISA had “no significant risk or known exploitation.” That is the agency’s statement, not independent proof that exploitation never occurred. The CVE documents a possible execution path, not confirmed attacks, and the reviewed reporting provides no victim count or incident-impact figures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Rank #3
Sale
Secure Software Design: .
  • Used Book in Good Condition

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.