Executive brief
Arket Globe Document Intelligence, a platform used for managing business documents and workflows, contains a security vulnerability that allows attackers to inject malicious scripts into document titles. If an employee or administrator views the 'Task in Progress' or 'Recent' pages containing these documents, the script could automatically run in their browser. This could lead to unauthorized access to user accounts, theft of login sessions, or the exposure of sensitive corporate documents.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Arket Globe Document Intelligence version 5.0.0.559. The root cause is improper output encoding of the 'Title' property when rendering documents on summary pages such as 'Task in Progress / Recent'. An authenticated attacker can exploit this by creating or modifying a document and injecting a malicious script into the Title field. When other users, including administrators, view the affected summary pages, the payload executes in their browser context. This can be leveraged for session hijacking via cookie exfiltration or performing unauthorized actions on behalf of the victim. The vendor has released version 5.1.0.575 to address this issue.
Affected products
- Arket (Bluenext) Globe Document Intelligence 5.0.0.559
Timeline
- 2026-06-04: disclosed: Initial NVD publication date
- 2026-06-04: advisory
- 2025-01-01: patched: Fixed in version 5.1.0.575 (exact date not specified, year inferred from CVE)