PT-2026-68808 · Unknown · Ail Framework

·

CVE-2026-71445

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AIL Framework (affected versions not specified)
Description A reflected cross-site scripting issue exists in the '/tag/add tags' endpoint. When a tag operation fails, the application returns the error value as an HTML response via the str(res[0]) function without proper output encoding. An attacker can exploit this by tricking an authenticated user into clicking a crafted link, allowing arbitrary JavaScript to execute in the victim's browser. This could enable the attacker to perform actions using the victim's session, access sensitive information, or modify data. The attack requires user interaction and does not necessarily require the attacker to have an account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the '/tag/add tags' endpoint to minimize the risk of exploitation.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71445

Affected Products

Ail Framework