CVE-2026-5026 is a stored Cross-Site Scripting (XSS) vulnerability found in an unspecified product, where an API endpoint serves SVG files without sanitizing their content. An attacker can upload malicious SVG files containing embedded JavaScript, which then executes when viewed by other users. This allows for the potential theft of authentication tokens, such as JWT access and refresh tokens, resulting in a CVSS score of 7.0 (HIGH) due to its network attack vector and high confidentiality impact. There is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:langflow:langflow:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.