6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigured default superset rule files.
Basic Information
ID
CVE-2026-23769
Source
naver
Published
Jan 16, 2026 at 05:23
Modified
Jan 16, 2026 at 14:05
Affected Product
Vendor
NAVER
Product
lucy-xss-filter
Version
e5826c0d26b4f546955279767bbe94e5c7ed3f15