Stored Cross-Site Scripting in AIL Project Chat and Forum Features
CVE-2026-71447
6.9MEDIUM
What is CVE-2026-71447?
The AIL Project is vulnerable to a stored cross-site scripting (XSS) scenario via translation controls in chat messages and forum posts. The affected templates improperly insert message and post identifiers into inline JavaScript onclick handlers without appropriate encoding for safe usage as JavaScript string literals. This vulnerability allows attackers to inject arbitrary JavaScript code into the event handler, which can be executed in the context of a user's browser when they interact with the 'Translate to preferred language' feature. The malicious code can persist and potentially impact any analyst who accesses the related chat or forum view. Users are advised to apply patches to mitigate this security risk.
Affected Version(s)
ail-framework 0 <= 7.0.0
