These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS) via user-supplied data from imported crawler captures. This vulnerability allows attackers to inject malicious scripts, potentially leading to session hijacking, data exfiltration, or unauthorized actions. Defenders managing AIL Framework deployments, especially those with user-role API [truncated]
CVE-2026-100187 is a vulnerability in the Onion module of the AIL Framework. The vulnerability allowed unauthenticated attackers to inject arbitrary non-onion targets into the crawler's task queue by publishing crafted URLs. This resulted in a loss of integrity in the crawler's target selection. The vulnerability was caused by a performance shortcut in the URL extraction logic that accepted URLs as valid [truncated]
CVE-2026-100177 AIL Framework crawler task creation API insufficient authorization check allows authenticated users to leak or exfiltrate session data from another organization's stored cookies. The vulnerability requires an authenticated user with the ability to create crawler tasks and know or guess a valid cookiejar UUID belonging to another organization. Defenders should assess exposure and prioritize [truncated]
The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the username timeline, the application renders these stored usernames into the DOM using D3's html() method in the tooltip. Because the username value (d.obj) is interpolated directl [truncated]
The AIL Framework tag selector component is vulnerable to stored cross-site scripting (XSS). An attacker with an authenticated account and permission to create custom tags could embed a malicious HTML payload in the tag name. When another authenticated user views a page with the tag selector, the malicious script executes in their browser context. The vulnerability requires authentication and specific per [truncated]
CVE-2026-100172 AI-assisted PatchSiren debrief based on the supplied source corpus. The AIL Framework contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content. An authenticated attacker who can influence matched, tracked, or tagged content may inject arbitrary HTML or JavaScript into these values. When a victim displays [truncated]
AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the crawler history can inject JavaScript syntax into the stored URL value.
AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error message, a crafted request could cause arbitrary HTML or JavaScript to be reflected in the resp [truncated]