PT-2026-90967 · Kagisearch · Smallweb
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
kagisearch smallweb versions up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf
Description
A remote cross site scripting issue exists in the Query String Rendering component within the
index() function of the app/sw.py file. The flaw is triggered by manipulating the qs argument. Exploitation requires a raw HTTP request containing unencoded double-quote characters in the query string, as standard browsers typically percent-encode these characters, meaning the attack is primarily feasible via raw sockets such as netcat or curl.Recommendations
Apply patch 00b68144e583f20a6b67e29cf01bc07f57979ffb to resolve the issue.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smallweb