关键漏洞信息 Title: forest forest <= 0.0.5 Improper Neutralization of Alternate XSS Syntax Description: - Forest <= 0.0.5 contains a stored XSS vulnerability in the user profile update functionality. The signature fields are not sanitized before storage, allowing authenticated attackers to inject malicious JavaScript code that executes when other users view the attacker's profile. Source:  User:  (UID 86629) Submission Date: 02/10/2026 04:37 AM (12 days ago) Moderation Date: 02/21/2026 06:42 PM (12 days later) Status: Accepted VulDB Entry: 347317 (rymcu Forest up to 0.0.5 User Profile UserInfoController.java updateUserInfo Cross Site Scripting) Points: 18