Impact
A cross‑site scripting vulnerability exists in the index function of app/sw.py in kagisearch smallweb. This flaw conforms to CWE‑79 and involves improper handling of input that can lead to code injection, aligning with CWE‑94. An attacker can deliver malicious script by sending a character in the query string. Because Werkzeug returns the raw request target, browsers normally percent‑encode quotes, but tools like netcat or curl can send the raw payload, allowing an attacker to inject and execute script in a victim’s browser.
Affected Systems
The affected product is kagisearch smallweb. No specific version range is published due to the rolling‑release model, but any release prior to the commit 00b68144e583f20a6b67e29cf01bc07f57979ffb is potentially vulnerable. Users should check for updates that include the patch.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate impact. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation. Exploitation requires a crafted raw HTTP request with an unencoded quote, which can be produced with netcat or curl, making it less likely to be automated, yet possible.
OpenCVE Enrichment