VulnSea

ail_framework vulnerabilities

CVEs whose affected-version data names the ail_framework package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-100174Medium· 5.1
today

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS)

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100172High· 8.5
today

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

▾ Twilightail project · ail frameworkvia NVD
CVE-2026-100187Medium· 6.9
today

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100177Medium· 6.3
today

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified tha…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100176High· 8.5
today

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS)

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the usernam…

▾ Twilightail project · ail frameworkvia NVD
CVE-2026-100190Medium· 6.3
today

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file path…

▾ Sunlitail project · ail frameworkvia NVD
ail_framework vulnerabilities (CVEs) · VulnSea