ail project
ail framework
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-100190 | 25 Sep 2026 | ail framework: unspecified < 7.1 | The fix removes all capture-derived values (item IDs, URLs, screenshot paths) from inline JavaScript contexts (onclick attributes and inline script variable assignments). These values are now stored in HTML data attributes (data-screenshot, data-url, data-item-id), which are properly HTML-escaped by the Jinja2 template engine. Screenshot click handlers are bound programmatically via addEventListener on elements with a .reload-image class, and the reload_image function reads values from the DOM element's dataset rather than receiving raw string parameters. Additionally, item IDs are URL-encoded with encodeURIComponent before being appended to link hrefs, preventing injection through the ID field. | Update reference ↗ |
| CVE-2026-100187 | 25 Sep 2026 | ail framework: unspecified < 7.1 | The length-based shortcut that bypassed onion-domain validation is removed. Every extracted URL is now parsed using the standard URL domain extraction function, and the resulting hostname is validated against the existing onion-domain validation routine before the URL is added to the crawler task set. This ensures that only URLs whose hostname is a genuine .onion domain can be queued as crawler tasks. | Update reference ↗ |
| CVE-2026-100177 | 25 Sep 2026 | ail framework: unspecified < 7.1 | The cookiejar attachment path in api_add_crawler_task is now validated through the existing api_check_cookiejar_access_acl() function, which enforces organization, user, and role-based access control for the 'view' action on the referenced cookiejar. The user_role parameter is propagated from the API and UI entry points (api_rest.py, crawler_splash.py) into the ACL check. Separately, URL scheme validation is enforced unconditionally: only http and https schemes are accepted, and non-conforming URLs are rejected with a 400 error before any further processing. | Update reference ↗ |
| CVE-2026-100176 | 25 Sep 2026 | ail framework: unspecified < 7.1 | The fix applies the existing sanitize_text() helper to the user-controlled username value (d.obj) immediately before it is interpolated into the D3 tooltip HTML string. This ensures that any HTML or script content embedded in the stored username is neutralized before DOM insertion, preventing script execution while preserving the tooltip's intended formatting (line breaks and date/time display). | Update reference ↗ |
| CVE-2026-100174 | 25 Sep 2026 | ail framework: < 7.1 | The fix ensures that tag names and display values are rendered as plain text rather than as HTML when no custom renderer is explicitly configured. In the suggestion rendering path, the default (non-renderer) case now uses jQuery's .text() method, which HTML-escapes the content. In the selection rendering path, the default case uses document.createTextNode() to insert the value as a text node. Custom renderers, which are developer-supplied and trusted to produce safe HTML, continue to use .html() or .prepend() with raw HTML. The eval() call was also replaced with JSON.parse() to eliminate a code-injection vector. | Update reference ↗ |
| CVE-2026-100172 | 25 Sep 2026 | ail framework: unspecified < 7.1 | The fix applies double HTML-escaping (Jinja2 forceescape|forceescape) to every dynamic value interpolated into the HTML-enabled data-content attribute of the popover elements in both templates. Double-escaping is required because the values must survive both the outer HTML attribute context and the inner HTML parsing performed by the popover plugin. This neutralizes any HTML or script injection from the extracted-match fields. | Update reference ↗ |
| CVE-2026-76164 | 19 Aug 2026 | < 7.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-71447 | 6 Aug 2026 | ≤ 7.0.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-71446 | 6 Aug 2026 | ≤ 7.0.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-71445 | 6 Aug 2026 | ≤ 7.0.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-59510 | 5 Jul 2026 | ≤ v6.9.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-56450 | 22 Jun 2026 | ≤ 6.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-56448 | 22 Jun 2026 | ≤ 6.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-56138 | 19 Jun 2026 | < 6.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-39416 | 8 Apr 2026 | < 6.8 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.