Impact
The vulnerability occurs in the /tag/add_tags endpoint of the AIL Framework where an error message that contains attacker‑controlled input is reflected back in an HTML response without proper encoding. This allows an attacker to inject arbitrary JavaScript that will run in the browser of a user who is authenticated to the application. The impact is that the attacker can execute code within the victim’s browser session, potentially accessing or manipulating data that the victim can normally reach, or performing actions that appear to come from the victim’s account.
Affected Systems
Affected vendor: ail‑project. Product: ail‑framework. No specific version information is provided; the issue exists in any release prior to any future patch containing the commit referenced in the advisories.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation yet. The attack vector requires an authenticated user to open a crafted link; the attacker does not need an AIL Framework account themselves but must deliver the exploit to an already authenticated user. Successful exploitation would give the attacker code execution in the victim’s browser under the security context of the application.
OpenCVE Enrichment