PatchSiren cyber security CVE debrief
CVE-2026-39683 Chief Gnome CVE debrief
A DOM-Based XSS vulnerability was found in the Garden Gnome Package, affecting versions from n/a through <= 2.4.1. The issue has a CVSS score of 5.9 and a severity of MEDIUM. This type of vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. Users of affected versions should be aware of this vulnerability and take necessary precautions to protect their deployments.
- Vendor
- Chief Gnome
- Product
- Garden Gnome Package
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Garden Gnome Package versions prior to 2.4.1 should be aware of this vulnerability and take necessary precautions. This includes reviewing and applying patches or updates, implementing compensating controls such as input validation and output encoding, and monitoring for suspicious activity and exception tracking. Security teams and operators managing affected deployments should prioritize mitigation efforts.
Technical summary
The CVE-2026-39683 vulnerability is a DOM-Based XSS issue in the Garden Gnome Package. It affects Garden Gnome Package versions from n/a through <= 2.4.1. The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM. DOM-Based XSS vulnerabilities occur when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages.
Defensive priority
MEDIUM
Recommended defensive actions
- Inventory and verify affected Garden Gnome Package versions
- Apply patches or updates to Garden Gnome Package versions prior to 2.4.1
- Implement compensating controls, such as input validation and output encoding
- Monitor for suspicious activity and exception tracking
- Review official advisories and CVE records for mitigation guidance
Evidence notes
The CVE record was published on 2026-04-08T09:16:40.140Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability affects Garden Gnome Package versions from n/a through <= 2.4.1, and has a CVSS score of 5.9 with a severity of MEDIUM. Users should verify their deployments and review official advisories for mitigation guidance.
Official resources
-
CVE-2026-39683 CVE record
CVE.org
-
CVE-2026-39683 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:40.140Z and has not been modified since then. The NVD entry is currently Deferred.