Executive brief
Pentestify is a pentest report generation and management application used by security professionals to document and share findings with clients. An authenticated user can inject malicious JavaScript code through a finding's severity field, which is then executed in the browsers of anyone viewing the report. This allows attackers to steal session cookies, deface reports, or redirect users to malicious sites.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the finding renderer component. The backend accepted the severity field without validation, and the frontend interpolated it unescaped into HTML class and style attributes (e.g., `severity-<x>` and `var(--severity-<x>)`). An authenticated attacker could break the attribute boundary using `">` and inject an `<img onerror>` tag or similar payload to execute arbitrary JavaScript in the context of the application. The fix, released in v2.3.2, implements a whitelist of permitted severity values (crit, high, med, low, info) on both backend and frontend, and sanitizes output in all rendering sinks.
Affected products
- maalfer Pentestify before 2.3.1
Timeline
- 2026-08-11: disclosed: CVE-2026-19434 published
- 2026-07-17: patched: Fix committed; v2.3.2 released