Description
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these fields, the application fails to properly sanitize or escape the content. As a result, the injected script is executed when the page is rendered, allowing the attacker to execute arbitrary JavaScript in the context of other users' browsers who view the affected page.
Published: 2026-06-04
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Scripting flaw that appears on the "Task in Progress / Recent" page of Arket Globe Document Intelligence version 5.0.0.559. When an authenticated user creates a new document, text fields are not properly sanitized or escaped, allowing an attacker to inject JavaScript code. When other users subsequently view the affected page, the browser executes the malicious script in the context of those users, potentially enabling theft of session cookies, credential hijacking, or other malicious client‑side actions. The weakness corresponds to the CWE‑79 defect model for untrusted input used in client‑side rendering.

Affected Systems

Arket Globe Document Intelligence 5.0.0.559 is the only product identified as affected. No additional vendor or product variants are listed.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The impact is limited to client browsers and requires that the attacker be authenticated to create the malicious document, but once injected, any user who views the page can be compromised. Without a public patch, the exploitation vector remains an internal authenticated user injecting payloads that are later rendered for other users. The CVSS score of 6.3 indicates medium severity, while the EPSS is not available and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet.

Generated by OpenCVE AI on June 4, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Arket Globe Document Intelligence to the latest patched release once available.
  • Implement server‑side validation and escaping of all user‑supplied text fields, ensuring that any data displayed to browsers is sanitized.
  • Configure a Content Security Policy (CSP) to restrict JavaScript execution contexts and mitigate the impact of any residual or discovered XSS vectors.

Generated by OpenCVE AI on June 4, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arket
Arket globe Document Intelligence
Vendors & Products Arket
Arket globe Document Intelligence

Thu, 04 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Title Arket Globe Document Intelligence XSS in Task Page Due to Improper Input Sanitization

Thu, 04 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Title Arket Globe Document Intelligence XSS in Task Page Due to Improper Input Sanitization

Thu, 04 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these fields, the application fails to properly sanitize or escape the content. As a result, the injected script is executed when the page is rendered, allowing the attacker to execute arbitrary JavaScript in the context of other users' browsers who view the affected page.
References

Subscriptions

Arket Globe Document Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-04T18:51:32.219Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65640

cve-icon Vulnrichment

Updated: 2026-06-04T18:50:31.374Z

cve-icon NVD

Status : Received

Published: 2026-06-04T19:16:25.620

Modified: 2026-06-04T20:16:56.770

Link: CVE-2025-65640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:11:01Z

Weaknesses