Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100190— Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page

Quick assessment

Affected
ail project ail framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AIL 框架的爬虫抓图页面(showDomain.html)存在存储型跨站脚本(XSS)漏洞。源自导入的爬虫抓取数据中的用户可控数据——具体包括项目 ID、URL 以及截图文件路径——被直接插值嵌入到 HTML 模板中的内联 JavaScript 上下文中。这其中包括一个 onclick 属性,该属性将原始的截图和 URL 值嵌入到 JavaScript 函数调用中,以及一个内联脚本块,该脚本块将截图值直接赋值给一个 JavaScript 变量,而未进行任何转义处理。拥有用户角色 API 客户端的攻击者可以构造一个

CVSS 6.3 · Medium EPSS 0.32% · P22

Affected Version Matrix 1

VendorProduct Version RangeStatus
ail project ail framework unspecified< 7.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100190

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page
Source: CVE Program / CVE List V5
Vulnerability Description
The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file paths—was interpolated directly into inline JavaScript contexts within the HTML template. This included an onclick attribute that embedded raw screenshot and URL values into a JavaScript function call, and an inline script block that assigned a screenshot value to a JavaScript variable without escaping. An attacker with a user-role API client could craft a malicious crawler capture import containing JavaScript payloads in these fields. When any user (including privileged users) subsequently viewed the affected domain page, the injected script would execute in the victim's browser context, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the victim. The vulnerability is stored in the application's data layer and triggered upon page rendering, requiring no further interaction beyond loading the domain view.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ail project ail framework unspecified ~ 7.1 -

II. Public POCs for CVE-2026-100190

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100190

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-100190 (1)

Same Patch Batch · ail project · 2026-09-25 · 6 CVEs total

CVE-2026-100172 8.5 HIGH Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-
CVE-2026-100176 8.5 HIGH Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip
CVE-2026-100187 6.9 MEDIUM AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain
CVE-2026-100177 6.3 MEDIUM Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Coo
CVE-2026-100174 5.1 MEDIUM Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names

IV. Related Vulnerabilities

V. Comments for CVE-2026-100190

No comments yet


Leave a comment