Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-51153

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 QD 版本 20220208 至 20250803 中, 中 函数存在存储型跨站脚本(Stored XSS)漏洞。 当通过 触发任务运行时,该处理程序会使用 Python 的 字符串格式化将任务日志内容( )渲染到 HTML 响应中,但未对内容进行 HTML 转义。 的数据来源于异常对象或通过 变量,而该变量可被攻击者通过模板的 机制控制。 一个低权限的已认证攻击者可以构造一个特制的 HAR 模板,借助 端点,将任意的 HTML/JavaScript 代码提取到 变量中。当受害者触发任务运行时,嵌入的脚本会在其

AI Predicted 7.2 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51153

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 through 20250803. When a task is run via /task/<taskid>/run, the handler renders task log content (logtmp) into the HTML response using Python % string formatting without HTML encoding. logtmp is populated from the exception object or from new_env.variables.__log__, which is attacker-controlled via the template extract_variables mechanism. A low-privileged authenticated attacker can create a crafted HAR template that extracts arbitrary HTML/JavaScript into the __log__ variable via the api://util/unicode endpoint. When a victim triggers the task run, the embedded script executes in the victim browser within the QD application context.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51153

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51153

登录查看更多情报信息。

Other References for CVE-2026-51153 (1)

Same Patch Batch · n/a · 2026-08-31 · 64 CVEs total

CVE-2026-82608 7.4 HIGH Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds
CVE-2026-82630 7.3 HIGH PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection
CVE-2026-82600 7.3 HIGH SeaCMS zyapi.php sql injection
CVE-2026-82598 7.3 HIGH SeaCMS Template search.php parseIf code injection
CVE-2026-82603 5.4 MEDIUM SeaCMS Comment Cache member.php del_pl path traversal
CVE-2026-82599 5.4 MEDIUM SeaCMS Avatar Upload member.php unlink path traversal
CVE-2026-82623 5.3 MEDIUM open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange
CVE-2026-82602 5.3 MEDIUM SeaCMS ass.php authorization
CVE-2026-82601 4.3 MEDIUM SeaCMS err.php cross site scripting
CVE-2026-82805 4.3 MEDIUM Typora Mermaid Rendering cross site scripting
CVE-2026-82596 3.3 LOW LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru
CVE-2026-51152 QD多个版本/har/test接口未认证SSRF漏洞
CVE-2026-51692 TOTOLINK T6 4.1.5cu.748_B20211015 访客WiFi访问控制漏洞
CVE-2026-51704 TOTOLINK T6 4.1.5 未授权访问控制漏洞
CVE-2026-51705 TOTOLINK T6 4.1.5 未认证下 Mesh 名称越权
CVE-2026-51702 TOTOLINK T6 4.1.5 未认证访问控制漏洞
CVE-2026-51699 TOTOLINK T6 4.1.5 认证绕过漏洞
CVE-2026-51701 TOTOLINK T6 4.1.5 未授权访问控制漏洞
CVE-2026-51694 TOTOLINK T6 4.1.5 静态DHCP规则访问控制不当漏洞
CVE-2026-51718 TOTOLINK T6 4.1.5 未认证访问控制缺陷

Showing top 20 of 64 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-51153

No comments yet


Leave a comment