← All research

GHSA-x738-j22q-h2jw

Stored and reflected XSS via unsanitized Markdown in Scenario descriptions

01Record

IdentifierGHSA-x738-j22q-h2jw
ProjectHuginn
ComponentScenario descriptions
CWECWE-79
CVSS8.1
Disclosed2026-09-08
Endor referenceENDOR-VUL-2026-2708

02Detail

Description: Huginn rendered Scenario descriptions through Kramdown and marked the result html_safe without sanitization, so raw HTML such as <script> elements, event handler attributes and javascript: links passed through verbatim. The icon of an imported Scenario was likewise stored without validation and interpolated into markup without escaping. Affects versions up to 2026.08.27; fixed in 2026.09.08.

Impact: Cross-Site Scripting. An attacker needs no Huginn account, only a victim who starts importing an attacker-supplied Scenario; the import preview renders the description before the import is confirmed. The script runs with the importing user's session and can read stored credentials or, for an administrator, create further administrators.

Discovered by Peyton Kennedy (p80n), bugbunny-research, kah-ja, ya3raj.