Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 15 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circl
Circl ail Framework |
|
| CPEs | cpe:2.3:a:circl:ail_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Circl
Circl ail Framework |
|
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ail-project
Ail-project ail-framework |
|
| Vendors & Products |
Ail-project
Ail-project ail-framework |
Wed, 08 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned without an explicit text/plain content type, allowing the browser to interpret the response as active HTML. This could result in execution of arbitrary JavaScript in the context of an authenticated user viewing a crafted item. This vulnerability is fixed in 6.8. | |
| Title | Stored XSS in modal item preview for long item content in AIL Framework | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T20:22:54.635Z
Reserved: 2026-04-07T00:23:30.595Z
Link: CVE-2026-39416
No data.
Status : Analyzed
Published: 2026-04-08T21:16:59.167
Modified: 2026-04-15T19:20:02.903
Link: CVE-2026-39416
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:27:26Z