PatchSiren cyber security CVE debrief
CVE-2026-82664 yaojingang CVE debrief
A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Handler. The manipulation of the argument Search leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.1.1 is able to mitigate this issue. The identifier of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is recommended. Users of yaojingang GEOFlow up to version 2.1.0 should verify their inventory and apply patches or upgrades. Additionally, security teams and vulnerability management teams should review the affected component and plan for mitigations or updates through normal change control processes. This vulnerability could allow attackers to inject malicious scripts into the application, potentially leading to unauthorized actions or data exposure.
- Vendor
- yaojingang
- Product
- GEOFlow
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-31
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-31
- Advisory updated
- 2026-08-31
Who should care
Users of yaojingang GEOFlow up to version 2.1.0 should verify their inventory and apply patches or upgrades. Additionally, security teams and vulnerability management teams should review the affected component and plan for mitigations or updates through normal change control processes. System administrators and security personnel responsible for managing and securing GEOFlow deployments should prioritize this vulnerability and take immediate action to mitigate the risk. IT teams and cybersecurity professionals should also be aware of the potential impact and take steps to protect their systems and data. Furthermore, developers and DevOps teams should review the affected code and implement necessary fixes to prevent similar vulnerabilities in the future. Vulnerability management teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Security teams should monitor for publicly disclosed exploit attempts and review system logs for potential exploitation attempts. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Finally, security teams should check relevant monitoring, detection, and logs for exposed assets that need extra review and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. The affected component and vulnerability class should be reviewed to understand the likely operational impact and source-confidence limits. The CVE record and official advisory should be reviewed to validate affected scope, severity, and vendor guidance. System administrators and security personnel should also review compensating controls for exposed systems while remediation is scheduled and verified. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Security teams should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review the supplied official
Technical summary
A cross-site scripting vulnerability affects yaojingang GEOFlow up to 2.1.0 in the JSON-LD Theme Handler. The issue is remotely exploitable via the Search argument. This vulnerability could allow attackers to inject malicious scripts into the application, potentially leading to unauthorized actions or data exposure. The vulnerability has been publicly disclosed and can be mitigated by upgrading to version 2.1.1 or applying the patch 67abfd864a15d169a78429f3290c91cb3b93e849.
Defensive priority
Low-priority defensive review recommended due to limited attack surface and low CVSS score.
Recommended defensive actions
- Verify inventory for vulnerable GEOFlow versions up to 2.1.0
- Apply patch 67abfd864a15d169a78429f3290c91cb3b93e849 or upgrade to version 2.1.1
- Monitor for publicly disclosed exploit attempts
- Review system logs for potential exploitation attempts
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence is limited; primary official records indicate a cross-site scripting vulnerability in yaojingang GEOFlow up to 2.1.0. Verify affected scope and inventory for vulnerable versions. Limited source detail suggests verifying deployment configurations and reviewing system logs for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82664 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82664
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82664 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82664
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/yaojingang/GEOFlow/
-
Source reference
Unverified legacy reference
URL: https://github.com/yaojingang/GEOFlow/commit/67abfd864a15d169a78429f3290c91cb3b93e849
-
Source reference
Unverified legacy reference
URL: https://github.com/yaojingang/GEOFlow/issues/60
-
Source reference
Unverified legacy reference
URL: https://github.com/yaojingang/GEOFlow/pull/61
-
Source reference
Unverified legacy reference
URL: https://github.com/yaojingang/GEOFlow/releases/tag/v2.1.1
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-82664
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/893851
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/397158
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.