Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY15 SECURITY RECORDS

ail project

ail framework

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-100190 25 Sep 2026 ail framework: unspecified < 7.1 The fix removes all capture-derived values (item IDs, URLs, screenshot paths) from inline JavaScript contexts (onclick attributes and inline script variable assignments). These values are now stored in HTML data attributes (data-screenshot, data-url, data-item-id), which are properly HTML-escaped by the Jinja2 template engine. Screenshot click handlers are bound programmatically via addEventListener on elements with a .reload-image class, and the reload_image function reads values from the DOM element's dataset rather than receiving raw string parameters. Additionally, item IDs are URL-encoded with encodeURIComponent before being appended to link hrefs, preventing injection through the ID field. Update reference ↗
CVE-2026-100187 25 Sep 2026 ail framework: unspecified < 7.1 The length-based shortcut that bypassed onion-domain validation is removed. Every extracted URL is now parsed using the standard URL domain extraction function, and the resulting hostname is validated against the existing onion-domain validation routine before the URL is added to the crawler task set. This ensures that only URLs whose hostname is a genuine .onion domain can be queued as crawler tasks. Update reference ↗
CVE-2026-100177 25 Sep 2026 ail framework: unspecified < 7.1 The cookiejar attachment path in api_add_crawler_task is now validated through the existing api_check_cookiejar_access_acl() function, which enforces organization, user, and role-based access control for the 'view' action on the referenced cookiejar. The user_role parameter is propagated from the API and UI entry points (api_rest.py, crawler_splash.py) into the ACL check. Separately, URL scheme validation is enforced unconditionally: only http and https schemes are accepted, and non-conforming URLs are rejected with a 400 error before any further processing. Update reference ↗
CVE-2026-100176 25 Sep 2026 ail framework: unspecified < 7.1 The fix applies the existing sanitize_text() helper to the user-controlled username value (d.obj) immediately before it is interpolated into the D3 tooltip HTML string. This ensures that any HTML or script content embedded in the stored username is neutralized before DOM insertion, preventing script execution while preserving the tooltip's intended formatting (line breaks and date/time display). Update reference ↗
CVE-2026-100174 25 Sep 2026 ail framework: < 7.1 The fix ensures that tag names and display values are rendered as plain text rather than as HTML when no custom renderer is explicitly configured. In the suggestion rendering path, the default (non-renderer) case now uses jQuery's .text() method, which HTML-escapes the content. In the selection rendering path, the default case uses document.createTextNode() to insert the value as a text node. Custom renderers, which are developer-supplied and trusted to produce safe HTML, continue to use .html() or .prepend() with raw HTML. The eval() call was also replaced with JSON.parse() to eliminate a code-injection vector. Update reference ↗
CVE-2026-100172 25 Sep 2026 ail framework: unspecified < 7.1 The fix applies double HTML-escaping (Jinja2 forceescape|forceescape) to every dynamic value interpolated into the HTML-enabled data-content attribute of the popover elements in both templates. Double-escaping is required because the values must survive both the outer HTML attribute context and the inner HTML parsing performed by the popover plugin. This neutralizes any HTML or script injection from the extracted-match fields. Update reference ↗
CVE-2026-76164 19 Aug 2026 < 7.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71447 6 Aug 2026 ≤ 7.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71446 6 Aug 2026 ≤ 7.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71445 6 Aug 2026 ≤ 7.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-59510 5 Jul 2026 ≤ v6.9.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56450 22 Jun 2026 ≤ 6.8.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56448 22 Jun 2026 ≤ 6.8.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-56138 19 Jun 2026 < 6.8.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-39416 8 Apr 2026 < 6.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.