Cross-site scripting in NukeViet - CVE-2026-94598
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of a victim's page.
The vulnerability exists due to improper neutralization of input during web page generation in the NukeVietCoreRequest HTML sanitizer's filterTags() and filterAttr() functions when processing HTML content in an iframe srcdoc attribute. A remote attacker can submit crafted content containing forged internal marker sequences to execute arbitrary JavaScript in the context of a victim's page.
User interaction is required for a victim to view stored content containing the crafted iframe. Exploitation requires iframe to be included in the allowed HTML tags list.