Cross-site scripting in NukeViet - CVE-2026-94598

 

Cross-site scripting in NukeViet - CVE-2026-94598

Published: October 2, 2026


Vulnerability identifier: #VU153175
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-94598
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of a victim's page.

The vulnerability exists due to improper neutralization of input during web page generation in the NukeVietCoreRequest HTML sanitizer's filterTags() and filterAttr() functions when processing HTML content in an iframe srcdoc attribute. A remote attacker can submit crafted content containing forged internal marker sequences to execute arbitrary JavaScript in the context of a victim's page.

User interaction is required for a victim to view stored content containing the crafted iframe. Exploitation requires iframe to be included in the allowed HTML tags list.


Affected software

NukeViet

How to mitigate CVE-2026-94598

Install security update from vendor's website.

NukeViet - update to 4.6.02

External References

Related Security Bulletins