PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44669 factionsecurity CVE debrief

FACTION, a penetration testing report generation and collaboration framework, contains a stored cross-site scripting (XSS) vulnerability in versions prior to 1.8.3. The flaw exists in assessment file preview flows where user-supplied attachment filenames are persisted to the server and subsequently rendered into HTML and attribute contexts without proper output encoding. Because the malicious payload is stored server-side and delivered to other users viewing affected pages, the vulnerability enables persistent JavaScript execution in victim browsers, including those of privileged accounts. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N) indicates network attack vector, low attack complexity, low privileges required, user interaction required, changed scope, and high impacts to confidentiality and integrity with no availability impact. The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). A fix is available in version 1.8.3.

Vendor
factionsecurity
Product
faction
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-05-26
Advisory published
2026-05-26
Advisory updated
2026-05-26

Who should care

Organizations using FACTION for penetration testing report generation and collaboration, particularly those with multi-user environments where assessment files are shared across team members or with clients. Security teams responsible for application security testing platforms and developers maintaining FACTION deployments.

Technical summary

The vulnerability stems from insufficient output encoding when rendering user-controlled attachment filenames in assessment file preview interfaces. Attackers can craft filenames containing JavaScript payloads that execute when other users view the preview page. The stored nature of the flaw means a single malicious upload can compromise multiple subsequent viewers, including administrators or other high-privilege users. The fix in version 1.8.3 implements proper encoding of filename values in HTML and attribute contexts.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade FACTION to version 1.8.3 or later to remediate the stored XSS vulnerability
  • Review assessment file attachments and preview logs for suspicious filename patterns that may indicate prior exploitation attempts
  • Implement Content Security Policy (CSP) headers and output encoding defenses as defense-in-depth measures for file preview functionality
  • Audit user accounts with access to assessment file previews for anomalous activity, particularly privileged accounts
  • Validate and sanitize all user-supplied filename inputs at both client and server boundaries before persistence and rendering

Evidence notes

Vulnerability description and fix version confirmed via GitHub Security Advisory GHSA-f2jc-wx44-mr54 and release notes. CVSS vector and CWE classification sourced from NVD record. No evidence of active exploitation or CISA KEV inclusion at time of disclosure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44669 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44669

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44669 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44669

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.