8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Description
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who views the affected page. Because the payload is stored server-side and rendered to other users, exploitation is persistent and can impact privileged accounts. This vulnerability is fixed in 1.8.3.
AI Analysis
Stored cross-site scripting (XSS) vulnerability via attachment filenames in assessment file preview flows
Basic Information
ID
CVE-2026-44669
Source
GitHub_M
Published
May 26, 2026 at 17:43
Modified
May 26, 2026 at 18:25
Affected Product
Vendor
factionsecurity
Product
faction
Version
< 1.8.3
Affected Versions
factionsecurity faction < 1.8.3
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
FactionSecurity
Product
Faction
Version
< 1.8.3