Description
Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft malicious links with script-terminating sequences in the schemaApi or data parameters to execute arbitrary JavaScript in victim sessions and steal X-Auth-Token credentials.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client-side cross-site scripting that can steal authentication tokens
Action: Immediate Patch
AI Analysis

Impact

The Steedos Platform through version 3.0.15‑beta.47 contains a reflected cross-site scripting flaw in the anonymous /api/page/render endpoint. The vulnerability arises because query parameters are not An attacker can craft a malicious URL withApi or data parameters, causing arbitrary JavaScript to execute in the victim’s browser session. This script can then steal X‑Auth‑Token credentials that the user has stored in the session, enabling credential theft.

Affected Systems

All deployments of the Steedos Platform that expose the default anonymous /api/page/render API endpoint and run a version of15‑beta.47 are affected. The vulnerability is present in any environment that uses the standard configuration of the platform and allows anonymous access to that endpoint.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS score of <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation but still possible. However, the endpoint is publicly reachable and the payload can be delivered via a simple hyperlink, meaning that an attacker could realistically inject malicious scripts into a victim’s session. Successful exploitation would lead to credential theft that could allow lateral movement or unauthorized access within, especially for environments that rely on the default anonymous access policy.

Generated by OpenCVE AI on September 17, 2026 at 17:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Steedos Platform release (3.0.15 the XSS fix.
  • If an upgrade cannot be performed immediately, revoke all currently issued X‑Auth‑Token credentials and force users to re-authenticate.
  • Disable or restrict anonymous access to the /api/page/render endpoint, or add server‑side input validation that sanitizes query parameters and escapes script content.
  • Configure a strict content‑security‑policy header to block inline scripts and mitigate the impact of any residual XSS vulnerabilities.

Generated by OpenCVE AI on September 17, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft malicious links with script-terminating sequences in the schemaApi or data parameters to execute arbitrary JavaScript in victim sessions and steal X-Auth-Token credentials.
Title Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render
First Time appeared Steedos
Steedos steedos-platform
Weaknesses CWE-79
CPEs cpe:2.3:a:steedos:steedos-platform:*:*:*:*:*:*:*:*
Vendors & Products Steedos
Steedos steedos-platform
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Steedos Steedos-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:27.914Z

Reserved: 2026-09-15T10:42:43.305Z

Link: CVE-2026-91922

cve-icon Vulnrichment

Updated: 2026-09-15T12:39:59.318Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:12.737

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-91922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')