Executive brief
Allegra, a project management and collaboration platform, contains a security flaw in how it handles file attachments. An attacker can trick a user into clicking a malicious link or opening a specific file to execute unauthorized scripts in the user's browser. This could allow the attacker to perform actions on behalf of the user, potentially leading to unauthorized access to project data or account compromise.
Technical details
A stored cross-site scripting (XSS) vulnerability exists within the downloadAttachment method of the Allegra platform. The flaw is caused by insufficient validation of user-supplied data before it is rendered in the web interface. A remote attacker with low-level privileges can exploit this by inducing a victim to interact with a malicious page or file. Successful exploitation allows the execution of arbitrary JavaScript in the victim's session, which can be used to bypass authentication controls or perform unauthorized actions. The issue is addressed in Allegra version 9.0.0.
Affected products
- Alltena Allegra Versions prior to 9.0.0
Timeline
- 2025-10-08: disclosed: Vulnerability reported to vendor
- 2026-04-30: patched: Allegra 9.0.0 released
- 2026-06-11: advisory: ZDI advisory published
- 2026-06-13: other: CVE published in NVD