216.73.217.22

CVE-2026-27169

· Published 21/02/2026 00:16 · Modified 21/02/2026 00:16

Labels: CVE-2026-27169 2026-02-21CVE-2026-27169CWE-79[email protected]

Essential information

Published
21/02/2026 00:16
Modified
21/02/2026 00:16
Author
Creator
CVSS
8.9 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

CVSS metrics

Description

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to XSS. Stored content can execute JavaScript when later viewed in authenticated sessions. An attacker who can influence stored study/quiz/flashcard content could trigger script execution in a victim’s browser, potentially performing actions as that user in the local app session. This issue has been fixed in version 1.1.3-alpha.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
opensift / opensift cpe:2.3:a:opensift:opensift:<1.1.3-alpha:*:*:*:*:*:*:*

References