PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107801 banq CVE debrief

CVE-2026-107801 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, which allows authenticated attackers to execute JavaScript by uploading attachments with a specially crafted Content-Type. The vulnerability exists because the application serves uploaded files inline based on their Content-Type, allowing an attacker to upload a file with a Content-Type of text/html and share its link to execute JavaScript on the application's origin for viewing users.

Vendor
banq
Product
jivejdon
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Jivejdon deployments should assess exposure and verify the vulnerability in their inventory. This includes administrators and security teams managing Jivejdon instances, especially those allowing file uploads or serving files inline based on Content-Type.

Why it matters

CVE-2026-107801 is a stored XSS vulnerability in Jivejdon through 5.0, allowing authenticated attackers to execute JavaScript via attachment uploads. Defenders should prioritize verifying the vulnerability in their inventory and assessing exposure to mitigate potential impacts.

  • JavaScript execution on the application's origin for viewing users
  • Potential for attackers to perform actions on behalf of users
  • Possible theft of sensitive information or session hijacking
  • Defenders need to verify vulnerability and assess exposure in their inventory

Technical summary

The vulnerability exists in Jivejdon through version 5.0, where an authenticated attacker can upload a file with a specially crafted Content-Type, such as text/html, which is served inline by the UploadShowAction. This allows the attacker to execute JavaScript on the application's origin for viewing users. The vulnerability allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.

Defensive priority

Defenders should prioritize verifying the vulnerability in their inventory and assessing exposure, as it allows for JavaScript execution on the application's origin.

Recommended defensive actions

  • Verify Jivejdon version and assess exposure
  • Restrict file uploads to only serve files with expected Content-Types
  • Implement Content Security Policy to mitigate XSS
  • Monitor for suspicious attachment uploads and JavaScript execution
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details about the vulnerability, including its existence in Jivejdon through version 5.0 and the possibility of executing JavaScript via uploaded attachments. However, there is limited information on affected versions beyond 5.0 and no specific details on exploitation or victim impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107801 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107801

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107801 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107801

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107801.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/issues/28

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/UploadShowAction.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/upload/UploadHelper.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-attachment-upload-content-type

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.