PT-2026-21329 · Openshift · Openshift

Mdavistffhrtporg

·

Publicado

2026-02-20

·

Atualizado

2026-02-21

·

CVE-2026-27169

CVSS v3.1

8.9

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenSift versions 1.1.2-alpha and below
Description OpenSift is an AI study tool that utilizes semantic search and generative AI to process large datasets. The application renders untrusted user and model content in its chat tool user interface using unsafe HTML interpolation, resulting in a cross-site scripting (XSS) condition. Stored content can execute JavaScript when viewed in authenticated sessions. An attacker influencing stored study, quiz, or flashcard content could trigger script execution in a victim’s browser, potentially allowing actions to be performed as that user within the application session.
Recommendations Update to version 1.1.3-alpha or later.

Exploit

Correção

Improper Encoding or Escaping of Output

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-02354
CVE-2026-27169
GHSA-QRPX-7CMV-5GV5

Produtos afetados

Openshift