PT-2026-71082 · Unknown · Vulnerability-Lookup
CVSS v4.0
6.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vulnerability-Lookup (affected versions not specified)
Description
A stored cross-site scripting (XSS) issue exists in the
render tag badges Jinja filter used to display reference tags for vulnerability records. The application directly interpolates values from containers.cna.references[].tags[] into HTML badge elements and wraps the result in markupsafe.Markup, which bypasses Jinja's automatic HTML escaping. An authenticated user with vulnerability:create or vulnerability:modify permissions can submit crafted reference tags via the CNA API containing arbitrary HTML or JavaScript. This malicious content is stored and subsequently executed in the browser of any user visiting the public /cve/<id> or /vuln/<id> endpoints. This could allow an attacker to perform actions on behalf of the victim, access session information, or modify page content, potentially affecting unauthenticated users.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vulnerability-Lookup