Description
A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The patch is named 00b68144e583f20a6b67e29cf01bc07f57979ffb. It is recommended to apply a patch to fix this issue. Exploitability requires a raw HTTP request carrying unencoded double-quote characters in the query string - Werkzeug's request.query_string returns the raw request-target, and ordinary browsers percent-encode " as %22, so the payload only lands via netcat/curl-style raw sockets.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

A cross‑site scripting vulnerability exists in the index function of app/sw.py in kagisearch smallweb. This flaw conforms to CWE‑79 and involves improper handling of input that can lead to code injection, aligning with CWE‑94. An attacker can deliver malicious script by sending a character in the query string. Because Werkzeug returns the raw request target, browsers normally percent‑encode quotes, but tools like netcat or curl can send the raw payload, allowing an attacker to inject and execute script in a victim’s browser.

Affected Systems

The affected product is kagisearch smallweb. No specific version range is published due to the rolling‑release model, but any release prior to the commit 00b68144e583f20a6b67e29cf01bc07f57979ffb is potentially vulnerable. Users should check for updates that include the patch.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate impact. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation. Exploitation requires a crafted raw HTTP request with an unencoded quote, which can be produced with netcat or curl, making it less likely to be automated, yet possible.

Generated by OpenCVE AI on September 15, 2026 at 17:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch 00b68144e583f20a6b67e29cf01bc07f57979ffb to replace the vulnerable code path.
  • Pull the latest release from the kagisearch smallweb repository to ensure the fix is present.
  • As a temporary workaround, encode or otherwise sanitize injection of unencoded double‑quotes.

Generated by OpenCVE AI on September 15, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The patch is named 00b68144e583f20a6b67e29cf01bc07f57979ffb. It is recommended to apply a patch to fix this issue. Exploitability requires a raw HTTP request carrying unencoded double-quote characters in the query string - Werkzeug's request.query_string returns the raw request-target, and ordinary browsers percent-encode " as %22, so the payload only lands via netcat/curl-style raw sockets.
Title kagisearch smallweb Query String Rendering sw.py index cross site scripting
First Time appeared Kagisearch
Kagisearch smallweb
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:kagisearch:smallweb:*:*:*:*:*:*:*:*
Vendors & Products Kagisearch
Kagisearch smallweb
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Kagisearch Smallweb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:58:22.697Z

Reserved: 2026-09-12T17:36:40.109Z

Link: CVE-2026-90583

cve-icon Vulnrichment

Updated: 2026-09-15T17:58:00.842Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T20:16:51.837

Modified: 2026-09-15T18:19:37.187

Link: CVE-2026-90583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:29Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')