CVE-2026-66824
Received Received - Intake

Stored XSS in Capture Tree Visualization Page

Vulnerability report for CVE-2026-66824, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: 5a6e4751-2f3f-4070-9419-94fb35b644e8

Description

A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured and potentially attacker-controlled web content, a specially crafted value could prematurely terminate the surrounding <script> element and inject arbitrary HTML or JavaScript. The malicious code would execute in the browser of a user viewing the affected capture tree. Successful exploitation could allow an attacker to perform actions using the victim’s authenticated session, access information available to the victim, or modify application data within the permissions of the affected user. The patch removes the JSON data from the HTML document and retrieves it through a dedicated API endpoint. The client then processes the response using response.json(), preventing capture data from being interpreted as executable content within the original page’s HTML or JavaScript context.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in a capture tree visualization page. The application embedded serialized capture tree data directly into an inline JavaScript block using the Jinja safe filter. Attacker-controlled web content could terminate the script tag and inject malicious HTML or JavaScript, executing in the browser of any user viewing the affected capture tree.

Detection Guidance

This vulnerability is specific to a web application's capture tree visualization page and involves stored XSS via serialized data. Detection requires checking if the application embeds serialized capture tree data directly into JavaScript using the Jinja safe filter. Inspect the page source for inline script blocks containing serialized data from user-controlled inputs.

Impact Analysis

An attacker could exploit this to perform actions using your authenticated session, access your available information, or modify application data within your user permissions. Successful exploitation requires viewing the affected capture tree page.

Mitigation Strategies

Apply the vendor-provided patch that removes JSON data from the HTML document and retrieves it via a dedicated API endpoint. Ensure the client processes the response using response.json() to prevent execution of capture data as JavaScript. Review and sanitize all user-controlled inputs used in the capture tree visualization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66824. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart