PT-2026-81868 · Gazellepw · Gazellepw

·

CVE-2026-38466

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GazellePW (GazellePosterWall) versions prior to commit 86c4bedf727691b5a97af42a4864869d18446449
Description A Stored Cross-Site Scripting (XSS) issue exists in the torrent remaster custom title feature. Remote authenticated users can inject arbitrary JavaScript through the remaster custom title parameter. This script is stored during the torrent upload or edit process and is subsequently executed when the torrent title is rendered in the output.
Recommendations Update GazellePW (GazellePosterWall) to commit 86c4bedf727691b5a97af42a4864869d18446449 or a newer version. As a temporary mitigation, restrict the use of the remaster custom title parameter during torrent upload and editing.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38466

Affected Products

Gazellepw