PatchSiren

Lichess CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Lichess CVE published 2026-04-06

CVE-2026-35208

A server-side HTML injection vulnerability exists in Lichess, a free, adless, and open-source chess server. The issue allows approved streamers to inject arbitrary HTML into the /streamer and homepage 'Live streams' widget by placing markup in their Twitch/YouTube stream title. Although CSP is present and blocks inline script execution, the issue remains a server-side HTML injection sink. To trigger this, [truncated]