Junglewise Threat Intelligence

CVE-2026-25868: MiniGal Nano reflected XSS in index.php via dir parameter

CVE-2026-25868 · Severity: medium · CVSS 6.1 · Published 2026-02-11

Executive brief

MiniGal Nano, a lightweight PHP-based image gallery, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's web browser. By tricking a user into clicking a specially crafted link, an attacker could steal session information, redirect the user to malicious websites, or perform actions on the user's behalf within the gallery application. This issue affects all versions up to and including 0.3.5.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in MiniGal Nano version 0.3.5 and earlier. The vulnerability is located in index.php, where the application processes the 'dir' GET parameter to construct the $currentdir variable. This variable is subsequently embedded into an error message and returned to the user without proper output encoding or neutralization. An unauthenticated remote attacker can exploit this by persuading a victim to visit a URL containing malicious HTML or JavaScript code in the 'dir' parameter. Successful exploitation allows for arbitrary script execution in the context of the victim's browser session. As of the advisory date, the software appears to be unmaintained (unsupported when assigned).

Affected products

  • MiniGal MiniGal Nano 0.3.5 and prior

Timeline

  • 2026-02-11: disclosed: Initial disclosure by VulnCheck
  • 2026-02-11: advisory: NVD published the CVE entry

References

Related threats