Executive brief
OSCAL-GUI, a tool used for managing Open Security Controls Assessment Language (OSCAL) documents, is vulnerable to a security flaw that allows attackers to run malicious code in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could steal login session information or perform unauthorized actions on behalf of the user. This vulnerability affects the web interface used by security professionals to manage compliance documentation.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in OSCAL-GUI due to improper neutralization of the 'project' request parameter in 'oscal.php' and 'oscal-forms.php'. In 'oscal.php', the input is concatenated into a JavaScript string within a 'body onload' event handler without sanitization, allowing an attacker to break out of the attribute context. In 'oscal-forms.php', the parameter is reflected in error messages. An unauthenticated remote attacker can exploit this by persuading a user to visit a malicious URL, leading to arbitrary script execution in the context of the victim's session. The project was archived in March 2026, and no official patch is expected.
Affected products
- NIST / FedRAMP OSCAL-GUI <= commit c989c4b
Timeline
- 2026-03-27: other: Project archived by maintainers
- 2026-06-05: disclosed: Researcher disclosure published via GitHub Gist
- 2026-06-09: advisory: CVE published and VulnCheck advisory released