OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100176

HIGH · CVSS 8.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The AIL Framework's username timeline feature is susceptible to stored cross-site scripting (XSS) due to improper handling of user-generated content, allowing attackers to inject malicious JavaScript through crafted usernames. This vulnerability can lead to significant impacts such as session hijacking and unauthorized actions within the authenticated analyst's session when they interact with the timeline. Organizations using this Java-based framework, particularly those with analysts accessing the timeline feature, should prioritize remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100176
Severity
HIGH
CVSS
8.5
EPSS
0.35%
Java

Original NVD Description

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the username timeline, the application renders these stored usernames into the DOM using D3's html() method in the tooltip. Because the username value (d.obj) is interpolated directly into an HTML string without sanitization, a crafted username containing HTML event handlers (e.g., <img src=x onerror=alert(1)>) will execute arbitrary JavaScript in the analyst's browser when the analyst hovers over the corresponding timeline entry. The attack requires the victim to be an authenticated analyst with access to the timeline view and to interact with the malicious timeline entry (hover). Successful exploitation can lead to session hijacking, data exfiltration, or unauthorized actions performed within the analyst's authenticated session. The vulnerability resides in the client-side JavaScript file var/www/static/js/d3/timeline_basic.js.