Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100172— Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attributes

Quick assessment

Affected
ail project ail framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AIL 框架(ail-project/ail-framework)在两个用于渲染匹配、追踪或标记内容的弹出窗口(popover)的 Jinja2 模板中存在存储型跨站脚本(XSS)漏洞。受影响的模板文件为: 在这两个模板中,与上述内容关联的动态值(包括图标颜色、图标样式、图标字形、子类型、标识符、名称、描述以及匹配值)被直接插入了 Bootstrap 弹出窗口元素的 HTML 属性中,且未进行适当的输出编码。由于这些弹出窗口配置为 ,浏览器会将该内容解析为 HTML。 如果攻击者具有认证权限,并能影响匹配、追踪或标

CVSS 8.5 · High EPSS 0.27% · P17

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript

Affected Version Matrix 1

VendorProduct Version RangeStatus
ail project ail framework unspecified< 7.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100172

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attributes
Source: CVE Program / CVE List V5
Vulnerability Description
The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message.html and var/www/templates/objects/item/show_item.html. In both templates, dynamic values associated with this content, including icon color, icon style, icon glyph, subtype, identifier, name, description, and matched value, are interpolated directly into the data-content HTML attribute of Bootstrap popover elements without appropriate output encoding. Because the popovers are configured with data-html="true", the content is interpreted as HTML in the victim's browser. An authenticated attacker who can influence matched, tracked, or tagged content may inject arbitrary HTML or JavaScript into these values. When a victim displays the affected popover, the injected markup may execute in the victim's session, potentially enabling data exfiltration or actions with the victim's privileges. The vulnerability is classified as stored XSS because the malicious payload can persist in the affected match, tracking, or tag-related data and be delivered to users who view the affected content.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ail project ail framework unspecified ~ 7.1 -

II. Public POCs for CVE-2026-100172

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100172

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-100172 (1)

Same Patch Batch · ail project · 2026-09-25 · 6 CVEs total

CVE-2026-100176 8.5 HIGH Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip
CVE-2026-100187 6.9 MEDIUM AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain
CVE-2026-100177 6.3 MEDIUM Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Coo
CVE-2026-100190 6.3 MEDIUM Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain P
CVE-2026-100174 5.1 MEDIUM Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names

IV. Related Vulnerabilities

V. Comments for CVE-2026-100172

No comments yet


Leave a comment