Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Algonet
Algonet orcastatllm Researcher |
|
| CPEs | cpe:2.3:a:algonet:orcastatllm_researcher:1:*:*:*:*:*:*:* | |
| Vendors & Products |
Algonet
Algonet orcastatllm Researcher |
|
| Metrics |
cvssV3_1
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Algonetlab
Algonetlab orcastatllm-researcher |
|
| Vendors & Products |
Algonetlab
Algonetlab orcastatllm-researcher |
Fri, 06 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through malicious research topic inputs. | |
| Title | OrcaStatLLM Researcher Stored Cross-Site Scripting (XSS) via Log Message Injection in Session Page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T18:05:02.550Z
Reserved: 2026-01-27T19:35:20.530Z
Link: CVE-2026-24903
Updated: 2026-02-06T18:04:51.364Z
Status : Analyzed
Published: 2026-02-06T18:15:58.830
Modified: 2026-02-24T20:57:19.450
Link: CVE-2026-24903
No data.
OpenCVE Enrichment
Updated: 2026-04-17T22:45:29Z