Cross-Site Scripting Vulnerability in kagisearch smallweb Product
CVE-2026-90583

5.3MEDIUM

Key Information:

Vendor

Kagisearch

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90583?

A security flaw has been identified in the kagisearch smallweb product that affects the indexing functionality within the Query String Rendering component. This flaw enables cross-site scripting attacks that can be executed remotely. Attackers can exploit this vulnerability by manipulating the 'qs' argument, resulting in the execution of malicious scripts. Notably, the exploit can be launched using raw HTTP requests containing unencoded double-quote characters in the query string, as typical web browsers encode such characters. To mitigate this risk, users are urged to apply the designated patch promptly.

Affected Version(s)

smallweb 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Customeres (VulDB User)
.