Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55630— Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)

Quick assessment

Affected
kiwitcms Kiwi
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kiwi TCMS 是一个开源的测试管理系统。在 16.1 版本之前,TestCase.extra_link 和 TestPlan.extra_link 字段接收未经清理的用户输入,并将存储的值原样渲染,从而产生跨站脚本(XSS)攻击的风险。官方 Docker 镜像和未经修改的 Kiwi TCMS 中间件会发送 Content-Security-Policy(CSP)响应头,该策略会阻止内联 JavaScript 的执行,因此在默认部署下利用该漏洞较为困难;而经过定制、削弱了相关安全设置的部署仍可能保持易受攻击状态

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55630

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)
Source: CVE Program / CVE List V5
Vulnerability Description
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kiwitcms Kiwi < 16.1 -

II. Public POCs for CVE-2026-55630

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55630

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55630 (2)

Vendor Advisories for CVE-2026-55630 (1)

Vendor Pages for CVE-2026-55630 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55630

No comments yet


Leave a comment