Cross-site scripting in Kiwi - CVE-2023-36809
Published: July 4, 2023 / Updated: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper HTTP header configuration in Kiwi when rendering stored malicious content. A remote attacker can store malicious script content to execute arbitrary script in a victim's browser.
User interaction is required to trigger execution.