Junglewise Threat Intelligence

CVE-2026-40038: Pachno stored cross-site scripting via multiple parameters

CVE-2026-40038 · Severity: high · CVSS 7.2 · Published 2026-04-13

Executive brief

Pachno, an open-source project management and collaboration platform, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the system. These scripts are stored in the database and automatically execute in the browsers of other users, including administrators, when they view affected pages like comments or articles. This could lead to unauthorized actions being performed on behalf of users, theft of session information, or the defacement of the platform.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Pachno version 1.0.6 and below. The issue stems from improper input sanitization within the Request::getRawParameter() and Request::getParameter() methods across multiple controllers. An attacker can inject malicious JavaScript payloads into several POST parameters, including 'value', 'comment_body', 'article_content', 'description', and 'message'. Because these payloads are stored in the database and rendered without sufficient escaping, they execute in the context of any user's browser session who views the compromised content. This can be exploited by a remote attacker to steal session cookies, perform unauthorized actions, or conduct further client-side attacks.

Affected products

  • Pachno Pachno 1.0.6 and earlier

Timeline

  • 2026-04-13: advisory: Initial disclosure by VulnCheck and Zero Science Lab
  • 2026-04-13: disclosed: CVE-2026-40038 published

References