CVE-2026-34416
Received Received - Intake
Reflected XSS in OSCAL-GUI via project request parameter

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: VulnCheck

Description
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the project request parameter. Attackers can craft a malicious URL containing unsanitized input that breaks out of the JavaScript string and HTML attribute context in the body onload event handler to execute arbitrary scripts when the link is visited by a victim.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-10
AI Q&A
2026-06-10
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a reflected cross-site scripting (XSS) issue in OSCAL-GUI. It allows unauthenticated attackers to inject malicious JavaScript code into a victim's browser by manipulating the project request parameter. The attacker crafts a malicious URL containing unsanitized input that breaks out of the JavaScript string and HTML attribute context within the body onload event handler. When a victim clicks this malicious link, the injected script executes in their browser.

Impact Analysis

This vulnerability can impact you by allowing attackers to execute arbitrary JavaScript in your browser without authentication. This can lead to theft of sensitive information such as cookies, session tokens, or other private data accessible through the browser. It may also enable attackers to perform actions on behalf of the victim or redirect them to malicious sites.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34416. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart