# CVE-2025-55133: Stored XSS in the workspace topic name of Agora A stored Cross-site scripting (XSS) vulnerability in Agora release fall23-Alpha1 and earlier, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the workspace topic name which would be rendered in the UI of users who visit that workspace. Discovered by Jared Bieker, July 2025. # References