PT-2026-98849 · Unknown · Ail Framework

·

CVE-2026-100187

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AIL Framework (affected versions not specified)
Description The Onion module contains a flaw in its URL extraction logic due to a performance shortcut. The system validates .onion targets using only a length check of exactly 69 characters and a suffix check for ".onion", omitting proper hostname parsing or onion-domain validation. An unauthenticated attacker can embed a crafted URL containing an IP address or a non-onion hostname with a path ending in ".onion" into content crawled by the framework. This allows the injection of arbitrary non-onion targets into the crawler's task queue, potentially directing the framework toward unintended network resources and compromising the integrity of target selection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100187

Affected Products

Ail Framework