PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-38466 Mosasauroidea CVE debrief

The CVE-2026-38466 vulnerability is a Stored XSS issue in the torrent remaster custom title feature of GazellePW. An authenticated user can inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output. This vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. GazellePW users and administrators should be aware of this vulnerability and take necessary precautions to prevent exploitation. The CVE record was published on 2026-08-25T22:17:03.160Z and has not been modified since then. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed.

Vendor
Mosasauroidea
Product
GazellePW
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-08-31
Advisory published
2026-08-25
Advisory updated
2026-08-31

Who should care

GazellePW users and administrators, security teams monitoring for XSS vulnerabilities, and developers responsible for maintaining GazellePW installations should be aware of this vulnerability and take necessary precautions to prevent exploitation. Additionally, operators and platform administrators who use GazellePW should review their systems for potential exposure and implement compensating controls if necessary. Vulnerability management teams should prioritize patching and monitoring for suspicious activity. Security teams should also review their detection and response capabilities to ensure they can identify and respond to potential XSS attacks. Asset inventory and change management processes should be reviewed to ensure that all GazellePW installations are accounted for and up-to-date with the latest patches. Rollback and change window processes should also be reviewed to ensure that any changes to GazellePW can be quickly rolled back if necessary. Source tracking and monitoring should be implemented to detect and respond to potential exploitation attempts. Compensating controls such as web application firewalls or intrusion detection systems may be necessary to prevent exploitation until a patch is available. Monitoring and logging should be implemented to detect and respond to potential XSS attacks. Asset owners should be notified and involved in the remediation process to ensure that all necessary precautions are taken. Security teams should also review their incident response plans to ensure they are prepared to respond to potential XSS attacks. The CVE record was published on 2026-08-25T22:17:03.160Z and has not been modified since then. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. Authenticated users with limited privileges can inject JavaScript into torrent titles, potentially leading to stored XSS attacks. Prioritize patching and monitoring for suspicious torrent activity. Implement additional security measures to detect and prevent XSS attacks. Restrict user privileges to prevent unauthorized JavaScript injection.

Technical summary

The CVE-2026-38466 vulnerability is a Stored XSS issue in the torrent remaster custom title feature of GazellePW. An authenticated user can inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed. To exploit this vulnerability, an attacker would need to be an authenticated user with limited privileges. The vulnerability is considered MEDIUM severity, but it could potentially lead to stored XSS attacks if not properly patched.

Defensive priority

Authenticated users with limited privileges can inject JavaScript into torrent titles, potentially leading to stored XSS attacks. Prioritize patching and monitoring for suspicious torrent activity.

Recommended defensive actions

  • Apply patches or updates to GazellePW to fix the Stored XSS vulnerability
  • Monitor torrent uploads and edits for suspicious activity
  • Restrict user privileges to prevent unauthorized JavaScript injection
  • Implement additional security measures to detect and prevent XSS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2026-38466 record indicates a Stored XSS vulnerability in GazellePW's torrent remaster custom title feature. Authenticated users can inject JavaScript via the remaster_custom_title parameter, which is stored and later rendered in torrent titles. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-38466 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-38466

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-38466 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38466

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/app/Upload.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/classes/torrents.class.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/sections/torrents/takeedit.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://snaacky.com/1-click-exploit-chain-for-complete-gazellepw-database-compromise

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.