« Volver al listado

CVE-2026-44669

Estado: AplazadaAlta (8.7)—

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who views the affected page. Because the payload is stored server-side and rendered to other users, exploitation is persistent and can impact privileged accounts. This vulnerability is fixed in 1.8.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-79 stored XSS en nombres de archivo; CVSS UI:R indica interacción del usuario. JavaScript ejecutado en navegador (T1059.007). Acceso a cuentas privilegiadas por almacenamiento persistente (T1078).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44669",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44669",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T18:25:31.338980Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "factionsecurity",
          "product": "faction",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.8.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T18:16:50.420",
  "references": [
    {
      "url": "https://github.com/factionsecurity/faction/releases/tag/1.8.3",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/factionsecurity/faction/security/advisories/GHSA-f2jc-wx44-mr54",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/factionsecurity/faction/security/advisories/GHSA-f2jc-wx44-mr54",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who views the affected page. Because the payload is stored server-side and rendered to other users, exploitation is persistent and can impact privileged accounts. This vulnerability is fixed in 1.8.3."
    },
    {
      "lang": "es",
      "value": "FACTION es un Framework de Colaboración y Generación de Informes de PenTesting. Antes de la versión 1.8.3, Faction es vulnerable a cross-site scripting (XSS) almacenado a través de nombres de archivo adjuntos en los flujos de vista previa de archivos de evaluación. Los valores de nombre de archivo proporcionados por el usuario se persisten y luego se renderizan en contextos HTML/de atributos sin codificación de salida, permitiendo que JavaScript controlado por el atacante se ejecute en el navegador de cualquier usuario que vea la página afectada. Debido a que la carga útil se almacena en el servidor y se renderiza a otros usuarios, la explotación es persistente y puede impactar cuentas privilegiadas. Esta vulnerabilidad se corrige en la versión 1.8.3."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "security-advisories@github.com"
}