« Volver al listado

CVE-2026-23769

Estado: AnalizadaMedia (6.1)—

lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigured default superset rule files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23769",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve@navercorp.com"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-23769",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-16T14:05:44.631261Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@navercorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/naver/lucy-xss-filter",
          "vendor": "NAVER",
          "product": "lucy-xss-filter",
          "versions": [
            {
              "status": "unaffected",
              "version": "e5826c0d26b4f546955279767bbe94e5c7ed3f15",
              "versionType": "git"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-01-16T06:15:51.483",
  "references": [
    {
      "url": "https://cve.naver.com/detail/cve-2026-23769.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@navercorp.com"
    },
    {
      "url": "https://github.com/naver/lucy-xss-filter/pull/32",
      "tags": [
        "Patch"
      ],
      "source": "cve@navercorp.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@navercorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigured default superset rule files."
    },
    {
      "lang": "es",
      "value": "lucy-xss-filter antes del commit e5826c0 permite a un atacante ejecutar JavaScript malicioso debido a una sanitización incorrecta causada por archivos de reglas de superconjunto predeterminados mal configurados."
    }
  ],
  "lastModified": "2026-06-17T10:22:05.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:naver:lucy-xss-filter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE152946-8B7E-490F-986A-D584F6CC5D4D",
              "versionEndExcluding": "2025-06-08"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@navercorp.com"
}