CVE Feed

    Dashboard / CVE / CVE-2026-39416

    CVE-2026-39416

    AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned without an explicit text/plain content type, allowing the browser to interpret the response as active HTML. This could result in execution of arbitrary JavaScript in the context of an authenticated user viewing a crafted item. This vulnerability is fixed in 6.8.

    Published:Apr 8, 2026
    Last Modified:Apr 15, 2026
    EPS:Apr 8, 2026
    EPSS Score:0.00092
    CVSS Score:6.1

    Affected Products

    Vendor
    Ail-project
    Product
    Ail-framework
    Vendor
    Circl
    Product
    Ail Framework

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High