Stored XSS Vulnerability in AIL Framework Affects Open-Source Data Processing
CVE-2026-39416

8.5HIGH

Key Information:

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39416?

The AIL Framework, designed for collecting and processing unstructured data, has a vulnerability affecting its modal item preview functionality. An attacker could exploit this stored XSS issue by sending specially crafted item content exceeding 800 characters, which would be interpreted by the browser as active HTML instead of plain text. This flaw could allow the execution of arbitrary JavaScript within the authenticated user's session, thereby compromising the user's environment. Users are advised to upgrade to version 6.8 to mitigate this risk.

Affected Version(s)

ail-framework < 6.8

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.