PT-2026-48267 · Brian Ruf · Oscal-Gui

·

CVE-2026-34416

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OSCAL-GUI (affected versions not specified)
Description Reflected cross-site scripting occurs when unauthenticated attackers execute arbitrary JavaScript in a victim's browser. This is achieved by injecting malicious input through the project request parameter. Attackers can craft a malicious URL with unsanitized input that breaks out of the JavaScript string and HTML attribute context within the body onload event handler, triggering script execution when the link is visited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34416

Affected Products

Oscal-Gui