Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100174— Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names

Quick assessment

Affected
ail project ail framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述信息的中文翻译: AIL 框架中的标签选择器组件(位于 )存在存储型跨站脚本(Stored XSS)漏洞。拥有创建自定义标签权限的用户可以在标签名称中嵌入包含 JavaScript 事件处理器的 HTML 载荷(例如 或 )。当其他已认证用户打开包含该标签选择器的页面时,恶意标签名称会通过 jQuery 的 属性被插入到 DOM 中,导致嵌入的脚本在受害者浏览器的上下文中执行。 受影响的脆弱代码路径包括建议/组合项渲染( )以及已选标签的渲染逻辑。在这两种情况下,源自标签 的显示值被直接传递给 j

CVSS 5.1 · Medium EPSS 0.40% · P32

Affected Version Matrix 1

VendorProduct Version RangeStatus
ail project ail framework < 7.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100174

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names
Source: CVE Program / CVE List V5
Vulnerability Description
The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g., <img src=x onerror=alert(1)> or <svg onload=...>) in the tag name. When another authenticated user opened a page containing the tag selector, the malicious tag name was inserted into the DOM using jQuery's html property, causing the embedded script to execute in the victim's browser context. The vulnerable code paths affected both the suggestion/combo-item rendering (_renderComboItems) and the selected-tag rendering logic. In both cases, the display value derived from the tag's displayField was passed directly to the html property of a jQuery element constructor, which parses and inserts the string as raw HTML rather than as text. Preconditions: the attacker must have an authenticated account with permission to create custom tags, and the victim must be an authenticated user who views a page that renders the tag selector with the attacker's stored tag. The attack is stored (persistent) and does not require the victim to perform any action beyond loading the page. Security impact: successful exploitation allows arbitrary JavaScript execution in the victim's browser within the application's origin, potentially leading to session hijacking, unauthorized data access, form manipulation, or further client-side attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ail project ail framework 0 ~ 7.1 -

II. Public POCs for CVE-2026-100174

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100174

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-100174 (1)

Same Patch Batch · ail project · 2026-09-25 · 6 CVEs total

CVE-2026-100172 8.5 HIGH Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-
CVE-2026-100176 8.5 HIGH Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip
CVE-2026-100187 6.9 MEDIUM AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain
CVE-2026-100177 6.3 MEDIUM Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Coo
CVE-2026-100190 6.3 MEDIUM Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain P

IV. Related Vulnerabilities

V. Comments for CVE-2026-100174

No comments yet


Leave a comment