{"api_version":"v1","generated_at":"2026-10-07T20:10:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-ail-project-ail-framework-8c757e379403","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ail framework","next_cursor":null,"observations":[{"affected":"ail framework: unspecified < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100190","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100190","fixed":"The fix removes all capture-derived values (item IDs, URLs, screenshot paths) from inline JavaScript contexts (onclick attributes and inline script variable assignments). These values are now stored in HTML data attributes (data-screenshot, data-url, data-item-id), which are properly HTML-escaped by the Jinja2 template engine. Screenshot click handlers are bound programmatically via addEventListener on elements with a .reload-image class, and the reload_image function reads values from the DOM element's dataset rather than receiving raw string parameters. Additionally, item IDs are URL-encoded with encodeURIComponent before being appended to link hrefs, preventing injection through the ID field.","last_modified":"2026-09-25T16:13:26.973Z","patch_url":"https://github.com/ail-project/ail-framework/commit/31376ee3d04519c898bb9b3671453a41c4117340","primary_source":"","published":"2026-09-25T13:52:19.648Z"},{"affected":"ail framework: unspecified < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100187","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100187","fixed":"The length-based shortcut that bypassed onion-domain validation is removed. Every extracted URL is now parsed using the standard URL domain extraction function, and the resulting hostname is validated against the existing onion-domain validation routine before the URL is added to the crawler task set. This ensures that only URLs whose hostname is a genuine .onion domain can be queued as crawler tasks.","last_modified":"2026-09-25T14:49:57.208Z","patch_url":"https://github.com/ail-project/ail-framework/commit/5c8a68b3d8c7d7b03e5febe4ac5b5aca91826adb","primary_source":"","published":"2026-09-25T13:42:16.854Z"},{"affected":"ail framework: unspecified < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100177","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100177","fixed":"The cookiejar attachment path in api_add_crawler_task is now validated through the existing api_check_cookiejar_access_acl() function, which enforces organization, user, and role-based access control for the 'view' action on the referenced cookiejar. The user_role parameter is propagated from the API and UI entry points (api_rest.py, crawler_splash.py) into the ACL check. Separately, URL scheme validation is enforced unconditionally: only http and https schemes are accepted, and non-conforming URLs are rejected with a 400 error before any further processing.","last_modified":"2026-09-25T14:55:51.640Z","patch_url":"https://github.com/ail-project/ail-framework/commit/3773ca36658c57ce592aebe74e27c855eb64f58a","primary_source":"","published":"2026-09-25T13:35:50.465Z"},{"affected":"ail framework: unspecified < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100176","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100176","fixed":"The fix applies the existing sanitize_text() helper to the user-controlled username value (d.obj) immediately before it is interpolated into the D3 tooltip HTML string. This ensures that any HTML or script content embedded in the stored username is neutralized before DOM insertion, preventing script execution while preserving the tooltip's intended formatting (line breaks and date/time display).","last_modified":"2026-09-25T14:59:28.644Z","patch_url":"https://github.com/ail-project/ail-framework/commit/455dd92c4179c53204368d93681ded4b57e31643","primary_source":"","published":"2026-09-25T13:29:17.333Z"},{"affected":"ail framework: < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100174","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100174","fixed":"The fix ensures that tag names and display values are rendered as plain text rather than as HTML when no custom renderer is explicitly configured. In the suggestion rendering path, the default (non-renderer) case now uses jQuery's .text() method, which HTML-escapes the content. In the selection rendering path, the default case uses document.createTextNode() to insert the value as a text node. Custom renderers, which are developer-supplied and trusted to produce safe HTML, continue to use .html() or .prepend() with raw HTML. The eval() call was also replaced with JSON.parse() to eliminate a code-injection vector.","last_modified":"2026-09-25T15:14:51.969Z","patch_url":"https://github.com/ail-project/ail-framework/commit/b2d0ed05f6cf79b2312a3f1f923d0d1a5d7a9edb","primary_source":"","published":"2026-09-25T13:22:38.669Z"},{"affected":"ail framework: unspecified < 7.1","affected_versions_present":true,"cve_id":"CVE-2026-100172","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100172","fixed":"The fix applies double HTML-escaping (Jinja2 forceescape|forceescape) to every dynamic value interpolated into the HTML-enabled data-content attribute of the popover elements in both templates. Double-escaping is required because the values must survive both the outer HTML attribute context and the inner HTML parsing performed by the popover plugin. This neutralizes any HTML or script injection from the extracted-match fields.","last_modified":"2026-09-25T15:19:12.598Z","patch_url":"https://github.com/ail-project/ail-framework/commit/ee63a0a96646790255e038f5ca5dd0ab5fe98db2","primary_source":"","published":"2026-09-25T13:13:56.996Z"},{"affected":"< 7.0","affected_versions_present":true,"cve_id":"CVE-2026-76164","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76164","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-19T15:44:51.882Z","patch_url":"","primary_source":"","published":"2026-08-19T08:53:13.458Z"},{"affected":"\u2264 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-71447","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71447","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T13:56:39.535Z","patch_url":"","primary_source":"","published":"2026-08-06T17:04:53.694Z"},{"affected":"\u2264 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-71446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71446","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T13:54:27.502Z","patch_url":"","primary_source":"","published":"2026-08-06T16:57:17.274Z"},{"affected":"\u2264 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-71445","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71445","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T13:55:55.951Z","patch_url":"","primary_source":"","published":"2026-08-06T16:48:50.682Z"},{"affected":"\u2264 v6.9.0","affected_versions_present":true,"cve_id":"CVE-2026-59510","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59510","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-06T13:22:56.591Z","patch_url":"","primary_source":"","published":"2026-07-05T17:52:29.429Z"},{"affected":"\u2264 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-56450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56450","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-22T15:48:49.228Z","patch_url":"","primary_source":"","published":"2026-06-22T13:02:30.320Z"},{"affected":"\u2264 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-56448","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56448","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-22T15:48:10.172Z","patch_url":"","primary_source":"","published":"2026-06-22T12:54:42.423Z"},{"affected":"< 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-56138","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56138","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-22T15:01:35.990Z","patch_url":"","primary_source":"","published":"2026-06-19T08:03:58.954Z"},{"affected":"< 6.8","affected_versions_present":true,"cve_id":"CVE-2026-39416","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39416","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T20:22:54.635Z","patch_url":"","primary_source":"","published":"2026-04-08T20:11:03.757Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"ail project"}}
