← Back

CVE-2026-27169

nvd nist
Published: Feb 21, 2026Modified: Feb 23, 2026

JSON object

Loading...
8.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Exploitability: 2.3 / Impact: 6.0
Source: security-advisories@github.com (Secondary)

Description

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to XSS. Stored content can execute JavaScript when later viewed in authenticated sessions. An attacker who can influence stored study/quiz/flashcard content could trigger script execution in a victim’s browser, potentially performing actions as that user in the local app session. This issue has been fixed in version 1.1.3-alpha.

Affected (1)

Products: Opensift: Opensift
1 product
Opensift
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.1.3

References (2)

Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.