PatchSiren

fastapi-admin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM fastapi-admin CVE published 2026-06-09

CVE-2026-36728

CVE-2026-36728 is a markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a chat message. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.4, indicating a MEDIUM severity level. The vulnerability was pu [truncated]