Junglewise Threat Intelligence

CVE-2026-10514: 1Panel-dev CordysCRM cross-site scripting in RequestParamTrimConfig

CVE-2026-10514 · Severity: low · CVSS 2.4 · Published 2026-06-02

Technologies: 1Panel-dev CordysCRM. Vendors: 1Panel-dev.

Executive brief

1Panel-dev CordysCRM, an open-source AI-powered CRM system, contains a security vulnerability that could allow an attacker to perform cross-site scripting (XSS). By exploiting this flaw, an attacker could inject malicious scripts into the application, potentially leading to unauthorized actions or the theft of sensitive session information from other users. This issue affects versions up to 1.6.2 and has been addressed in version 1.7.0.

Technical details

A cross-site scripting (XSS) vulnerability exists in 1Panel-dev CordysCRM versions up to 1.6.2. The flaw is located within the request parameter trimming configuration (RequestParamTrimConfig.java) in the backend framework. A remote attacker with high privileges can exploit this by injecting malicious scripts that are subsequently executed in the browser of another user. The root cause is improper neutralization of input during web page generation. The vulnerability is mitigated in version 1.7.0, which introduces configurable XSS protection and URL filtering.

Affected products

  • 1Panel-dev CordysCRM up to 1.6.2

Timeline

  • 2026-05-22: patched: Patch commit c87682afa8df79853299f75489c9d333f7bc5fce merged
  • 2026-05-29: advisory: Release v1.7.0 published with security fixes
  • 2026-06-02: disclosed: CVE-2026-10514 published

References

Related threats