Executive brief
The AIL framework, a tool used for analyzing large amounts of unstructured data, contains a security flaw in how it previews certain items. If an attacker uploads a specially crafted file or data entry, they can execute malicious code in the browser of an authorized user who views that item. This could allow the attacker to perform actions on behalf of the user or access sensitive information within the analysis platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the AIL framework's modal item preview functionality. The root cause is a failure to explicitly set a 'text/plain' content type when processing item content exceeding 800 characters, leading browsers to perform MIME-sniffing and execute the content as active HTML. An attacker with the ability to inject content into the framework can store malicious JavaScript that executes when an authenticated user views the crafted item's preview. This vulnerability is addressed in version 6.8.
Affected products
- ail-project ail-framework < 6.8
Timeline
- 2026-04-07: advisory: Initial advisory published by CIRCL/GitHub
- 2026-04-08: disclosed: CVE-2026-39416 published to NVD
- 2026-04-08: patched: Fix released in version 6.8