PatchSiren cyber security CVE debrief
CVE-2026-38466 Mosasauroidea CVE debrief
The CVE-2026-38466 vulnerability is a Stored XSS issue in the torrent remaster custom title feature of GazellePW. An authenticated user can inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output. This vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. GazellePW users and administrators should be aware of this vulnerability and take necessary precautions to prevent exploitation. The CVE record was published on 2026-08-25T22:17:03.160Z and has not been modified since then. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed.
- Vendor
- Mosasauroidea
- Product
- GazellePW
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
GazellePW users and administrators, security teams monitoring for XSS vulnerabilities, and developers responsible for maintaining GazellePW installations should be aware of this vulnerability and take necessary precautions to prevent exploitation. Additionally, operators and platform administrators who use GazellePW should review their systems for potential exposure and implement compensating controls if necessary. Vulnerability management teams should prioritize patching and monitoring for suspicious activity. Security teams should also review their detection and response capabilities to ensure they can identify and respond to potential XSS attacks. Asset inventory and change management processes should be reviewed to ensure that all GazellePW installations are accounted for and up-to-date with the latest patches. Rollback and change window processes should also be reviewed to ensure that any changes to GazellePW can be quickly rolled back if necessary. Source tracking and monitoring should be implemented to detect and respond to potential exploitation attempts. Compensating controls such as web application firewalls or intrusion detection systems may be necessary to prevent exploitation until a patch is available. Monitoring and logging should be implemented to detect and respond to potential XSS attacks. Asset owners should be notified and involved in the remediation process to ensure that all necessary precautions are taken. Security teams should also review their incident response plans to ensure they are prepared to respond to potential XSS attacks. The CVE record was published on 2026-08-25T22:17:03.160Z and has not been modified since then. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. Authenticated users with limited privileges can inject JavaScript into torrent titles, potentially leading to stored XSS attacks. Prioritize patching and monitoring for suspicious torrent activity. Implement additional security measures to detect and prevent XSS attacks. Restrict user privileges to prevent unauthorized JavaScript injection.
Technical summary
The CVE-2026-38466 vulnerability is a Stored XSS issue in the torrent remaster custom title feature of GazellePW. An authenticated user can inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed. To exploit this vulnerability, an attacker would need to be an authenticated user with limited privileges. The vulnerability is considered MEDIUM severity, but it could potentially lead to stored XSS attacks if not properly patched.
Defensive priority
Authenticated users with limited privileges can inject JavaScript into torrent titles, potentially leading to stored XSS attacks. Prioritize patching and monitoring for suspicious torrent activity.
Recommended defensive actions
- Apply patches or updates to GazellePW to fix the Stored XSS vulnerability
- Monitor torrent uploads and edits for suspicious activity
- Restrict user privileges to prevent unauthorized JavaScript injection
- Implement additional security measures to detect and prevent XSS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE-2026-38466 record indicates a Stored XSS vulnerability in GazellePW's torrent remaster custom title feature. Authenticated users can inject JavaScript via the remaster_custom_title parameter, which is stored and later rendered in torrent titles. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. The GazellePW project and specific commit are identified, but the vendor and product names are not confirmed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-38466 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-38466
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-38466 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38466
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/app/Upload.php
-
Source reference
Unverified legacy reference
URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/classes/torrents.class.php
-
Source reference
Unverified legacy reference
URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/sections/torrents/takeedit.php
-
Source reference
Unverified legacy reference
URL: https://snaacky.com/1-click-exploit-chain-for-complete-gazellepw-database-compromise
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.