Junglewise Threat Intelligence

CVE-2026-32774: Vulnogram stored cross-site scripting in comment handling

CVE-2026-32774 · Severity: low · CVSS 3.1 · Published 2026-03-16

Vendors: npm.

Executive brief

Vulnogram is a tool for managing and publishing security vulnerability advisories. A stored cross-site scripting (XSS) vulnerability in its comment feature allows attackers to inject malicious scripts that execute in other users' browsers when they view comments. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

The vulnerability is a stored cross-site scripting (CWE-79) flaw in Vulnogram's comment hypertext handling that affects version 1.0.0 and all previous versions. Attackers with network access can inject XSS payloads through comments; the payloads are persisted and executed in the browsers of any user viewing those comments. The attack requires user interaction (viewing the malicious comment) but does not require authentication to submit the payload. The vulnerability allows execution of arbitrary JavaScript in victims' browsers with access to the affected user's context. A patch is available via commit 2f0e21b113c58124084c7b74c9768fc241126a05.

Affected products

  • Vulnogram Vulnogram 1.0.0 and all previous versions

Timeline

  • 2026-03-16: disclosed
  • 2026-03-20: advisory: GitHub security advisory reviewed

References