Stored Cross-Site Scripting in AIL Project Chat and Forum Features
CVE-2026-71447

6.9MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-71447?

The AIL Project is vulnerable to a stored cross-site scripting (XSS) scenario via translation controls in chat messages and forum posts. The affected templates improperly insert message and post identifiers into inline JavaScript onclick handlers without appropriate encoding for safe usage as JavaScript string literals. This vulnerability allows attackers to inject arbitrary JavaScript code into the event handler, which can be executed in the context of a user's browser when they interact with the 'Translate to preferred language' feature. The malicious code can persist and potentially impact any analyst who accesses the related chat or forum view. Users are advised to apply patches to mitigate this security risk.

Affected Version(s)

ail-framework 0 <= 7.0.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Aurelien Thirion
.