PT-2026-68810 · Unknown · Project Ai

·

CVE-2026-71447

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AIL Project (affected versions not specified)
Description A stored cross-site scripting issue exists in the translation controls for chat messages and forum posts. The system inserts message and post identifiers directly into inline JavaScript onclick handlers within the functions translateMessageToPreferredLanguage() and translatePostToPreferredLanguage(). While these values are HTML-template escaped, they are not safely encoded for use as JavaScript string literals inside an HTML attribute. An attacker can use a specially crafted identifier containing quotation marks or escape characters to terminate the string argument and inject arbitrary JavaScript. Since these values are stored, the malicious code executes in the victim's browser under the security origin of the AIL instance when they click the Translate to preferred language button.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71447

Affected Products

Project Ai