Description
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
Published: 2026-09-15
Score: 0 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Immediate Patch
AI Analysis

Impact

Prior to version 16.1, Kiwi TCMS accepted arbitrary input in the TestCase.extra_link and TestPlan.extra_link fields, rendering stored values verbatim when the link is displayed. While the CVE description does not explicitly state the authentication requirement, it can be inferred that a user who can write these fields—typically an authenticated user—could inject a javascript: URI that will execute in the victim’s browser when the link is clicked, enabling session hijacking, privilege escalation, or defacement. Official builds send a Content‑Security‑Policy header that blocks inline JavaScript, which mitigates exploitation in default deployments, but deployments that disable or weaken this header remain vulnerable.

Affected Systems

All Kiwi TCMS installations using versions earlier than 16.1 are affected. The vulnerability applies to the default open‑source distribution as well as to modified deployments. Official Docker images and the unmodified middleware ship a Content‑Security‑Policy header that blocks inline JavaScript, which reduces the likelihood of successful exploitation in typical installations. Custom deployments that relax CSP configuration or otherwise weaken security controls remain vulnerable.

Risk and Exploitability

The EPSS score of less than 1 % indicates that exploitation is considered unlikely by current threat intelligence. This issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can create or edit a TestCase or TestPlan record; the attacker then injects a javascript: URI into the extra_link field. Successful exploitation depends on the victim viewing the affected link in a context where the CSP does not block inline scripts. Because the default configuration blocks inline scripts, the risk is mitigated on standard deployments, but customized configurations that remove or weaken the CSP header render the vulnerability exploitable. The likely attack vector is inferred to be an authenticated user who injects a malicious javascript: URI into these fields, as the description indicates that the application renders stored values verbatim.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kiwi TCMS to version 16.1 or newer, which sanitizes both fields and restores a safe default Content‑Security‑Policy header; do not disable inline script restrictions.
  • If upgrading is not immediately possible, locate and delete any entries in the TestCase.extra_link and TestPlan.extra_link database columns that contain a javascript: URI or other potentially malicious payloads.
  • Ensure that the Content‑Security‑Policy header continues to block inline scripts and that write access to the extra_link fields is restricted to trusted users only.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-473p-56xx-vg67 Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan & TestCase)
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
Title Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:23:18.544Z

Reserved: 2026-06-16T23:52:12.056Z

Link: CVE-2026-55630

cve-icon Vulnrichment

Updated: 2026-09-17T15:23:14.335Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:14.850

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')