PatchSiren cyber security CVE debrief
CVE-2026-39683 Chief Gnome CVE debrief
A DOM-Based XSS vulnerability was found in the Garden Gnome Package, affecting versions from n/a through <= 2.4.1. The issue has a CVSS score of 5.9 and a severity of MEDIUM. This type of vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. Users of affected versions should be aware of this vulnerability and take necessary precautions to protect their deployments.
- Vendor
- Chief Gnome
- Product
- Garden Gnome Package
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Garden Gnome Package versions prior to 2.4.1 should be aware of this vulnerability and take necessary precautions. This includes reviewing and applying patches or updates, implementing compensating controls such as input validation and output encoding, and monitoring for suspicious activity and exception tracking. Security teams and operators managing affected deployments should prioritize mitigation efforts.
Technical summary
The CVE-2026-39683 vulnerability is a DOM-Based XSS issue in the Garden Gnome Package. It affects Garden Gnome Package versions from n/a through <= 2.4.1. The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM. DOM-Based XSS vulnerabilities occur when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages.
Defensive priority
MEDIUM
Recommended defensive actions
- Inventory and verify affected Garden Gnome Package versions
- Apply patches or updates to Garden Gnome Package versions prior to 2.4.1
- Implement compensating controls, such as input validation and output encoding
- Monitor for suspicious activity and exception tracking
- Review official advisories and CVE records for mitigation guidance
Evidence notes
The CVE record was published on 2026-04-08T09:16:40.140Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability affects Garden Gnome Package versions from n/a through <= 2.4.1, and has a CVSS score of 5.9 with a severity of MEDIUM. Users should verify their deployments and review official advisories for mitigation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39683 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39683
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39683 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39683
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.