CVE-2026-97723

MEDIUMCVSS 5.4/10

Last modified

CVE-2026-97723 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML links.

Description

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML links. Quotation characters could break out of the generated href attribute and introduce attacker-controlled HTML attributes, allowing arbitrary JavaScript to execute in the browser of another user when the stored chat message was rendered. No click on the malicious link was required.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
madpsyka9q_ubersdr< 0.1.58

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-97723?
madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML links. Quotation characters could break out of the generated href attribute and introduce attacker-controlled HTML attributes, allowing arbitrary JavaScript to execute in the browser of another user when the stored chat message was rendered. No click on the malicious link was required.
How severe is CVE-2026-97723?
CVE-2026-97723 has a CVSS score of 5.4/10 (MEDIUM severity).
How do I fix CVE-2026-97723?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-97723?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST