PT-2026-90967 · Kagisearch · Smallweb

·

CVE-2026-90583

·

Published

2026-09-13

·

Updated

2026-09-15

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions kagisearch smallweb versions up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf
Description A remote cross site scripting issue exists in the Query String Rendering component within the index() function of the app/sw.py file. The flaw is triggered by manipulating the qs argument. Exploitation requires a raw HTTP request containing unencoded double-quote characters in the query string, as standard browsers typically percent-encode these characters, meaning the attack is primarily feasible via raw sockets such as netcat or curl.
Recommendations Apply patch 00b68144e583f20a6b67e29cf01bc07f57979ffb to resolve the issue.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90583

Affected Products

Smallweb