Onion module vulnerability in AIL Framework by AIL Project
CVE-2026-100187

6.9MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-100187?

The Onion module in AIL Framework is susceptible to a vulnerability where it incorrectly validates URLs based solely on their length and a suffix check for '.onion'. This flaw allows unauthenticated attackers to embed crafted URLs containing non-onion hostnames or IP addresses, which can then be processed as legitimate targets by the framework's crawling functionality. As a result, this vulnerability can lead to unauthorized influence over the crawler's operations, directing it towards unintended network resources and compromising the integrity of the target selection process.

Affected Version(s)

ail framework < 7.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aurelien Thirion
Jeroen Pinoy
.