PatchSiren cyber security CVE debrief
CVE-2026-107801 banq CVE debrief
CVE-2026-107801 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, which allows authenticated attackers to execute JavaScript by uploading attachments with a specially crafted Content-Type. The vulnerability exists because the application serves uploaded files inline based on their Content-Type, allowing an attacker to upload a file with a Content-Type of text/html and share its link to execute JavaScript on the application's origin for viewing users.
- Vendor
- banq
- Product
- jivejdon
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Jivejdon deployments should assess exposure and verify the vulnerability in their inventory. This includes administrators and security teams managing Jivejdon instances, especially those allowing file uploads or serving files inline based on Content-Type.
Why it matters
CVE-2026-107801 is a stored XSS vulnerability in Jivejdon through 5.0, allowing authenticated attackers to execute JavaScript via attachment uploads. Defenders should prioritize verifying the vulnerability in their inventory and assessing exposure to mitigate potential impacts.
- JavaScript execution on the application's origin for viewing users
- Potential for attackers to perform actions on behalf of users
- Possible theft of sensitive information or session hijacking
- Defenders need to verify vulnerability and assess exposure in their inventory
Technical summary
The vulnerability exists in Jivejdon through version 5.0, where an authenticated attacker can upload a file with a specially crafted Content-Type, such as text/html, which is served inline by the UploadShowAction. This allows the attacker to execute JavaScript on the application's origin for viewing users. The vulnerability allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.
Defensive priority
Defenders should prioritize verifying the vulnerability in their inventory and assessing exposure, as it allows for JavaScript execution on the application's origin.
Recommended defensive actions
- Verify Jivejdon version and assess exposure
- Restrict file uploads to only serve files with expected Content-Types
- Implement Content Security Policy to mitigate XSS
- Monitor for suspicious attachment uploads and JavaScript execution
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details about the vulnerability, including its existence in Jivejdon through version 5.0 and the possibility of executing JavaScript via uploaded attachments. However, there is limited information on affected versions beyond 5.0 and no specific details on exploitation or victim impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107801 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107801
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107801 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107801
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107801.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/issues/28
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/UploadShowAction.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/upload/UploadHelper.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-attachment-upload-content-type
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.