Emissary是National Security Agency开源的一个分布式 P2P 数据驱动工作流框架。 Emissary 8.39.0之前版本存在跨站脚本漏洞,该漏洞源于Mustache导航模板将配置控制的链接值直接插入href属性而未进行URL方案验证,可能导致能够修改navItems配置的管理员注入javascript: URI,从而对其他经过身份验证的用户实施存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NationalSecurityAgency | emissary | < 8.39.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35580 | 9.1 CRITICAL | Emissary has GitHub Actions Shell Injection via Workflow Inputs |
| CVE-2026-35581 | 7.2 HIGH | Emissary has a Command Injection via PLACE_NAME Configuration in Executrix |
| CVE-2026-35583 | 5.3 MEDIUM | Emissary has a Path Traversal via Blacklist Bypass in Configuration API |
No comments yet