Executive brief
Kiteworks is a platform used by organizations to securely share and manage sensitive data. A security flaw in the Secure Data Forms component could allow an attacker to trick a user into running malicious code in their web browser. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the user.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Kiteworks Secure Data Forms component due to improper neutralization of user-controllable input (CWE-79). An unauthenticated remote attacker can exploit this by inducing a user to click a specially crafted link, resulting in the execution of arbitrary JavaScript in the context of the user's browser session. This can lead to high confidentiality impact as session tokens or sensitive data may be accessed. The vulnerability was addressed in version 9.3.0 by entirely removing the affected Secure Data Forms feature from the product.
Affected products
- Kiteworks Secure Data Forms < 9.3.0
Timeline
- 2026-05-27: advisory: Vendor advisory published on GitHub
- 2026-06-01: disclosed: NVD publication date