GHSA-x738-j22q-h2jw
Stored and reflected XSS via unsanitized Markdown in Scenario descriptions
01Record
| Identifier | GHSA-x738-j22q-h2jw |
|---|---|
| Project | Huginn |
| Component | Scenario descriptions |
| CWE | CWE-79 |
| CVSS | 8.1 |
| Disclosed | 2026-09-08 |
| Endor reference | ENDOR-VUL-2026-2708 |
02Detail
Description: Huginn rendered Scenario descriptions through Kramdown and marked the result html_safe without sanitization, so raw HTML such as <script> elements, event handler attributes and javascript: links passed through verbatim. The icon of an imported Scenario was likewise stored without validation and interpolated into markup without escaping. Affects versions up to 2026.08.27; fixed in 2026.09.08.
Impact: Cross-Site Scripting. An attacker needs no Huginn account, only a victim who starts importing an attacker-supplied Scenario; the import preview renders the description before the import is confirmed. The script runs with the importing user's session and can read stored credentials or, for an administrator, create further administrators.
Discovered by Peyton Kennedy (p80n), bugbunny-research, kah-ja, ya3raj.