Junglewise Threat Intelligence

CVE-2026-40598: MantisBT HTML injection in tag update page

CVE-2026-40598 · Severity: medium · CVSS 4 · Published 2026-05-22

Technologies: mantisbt/mantisbt (Packagist), MantisBT. Vendors: Packagist, MantisBT.

Executive brief

MantisBT is an open-source software tool used by organizations to track software bugs and project issues. A security flaw in the system's tag update page could allow an attacker to inject malicious code into the application. While difficult to exploit in standard setups, it could lead to unauthorized actions or data theft if the system is used behind certain web caching or proxy servers.

Technical details

A reflected HTML injection vulnerability exists in MantisBT versions 2.28.1 and below within the 'tag_update_page.php' component. The application fails to properly escape the 'redirect' hidden input field, which is populated using the 'Referer' HTTP header. While modern browsers typically URL-encode the Referer header, preventing direct exploitation, an attacker could potentially achieve cross-site scripting (XSS) in environments utilizing server-side caching (like Varnish) or those susceptible to HTTP request smuggling. The vulnerability is exploited by sending a crafted Referer header containing HTML/JavaScript payloads. This issue is fixed in version 2.28.2 by implementing proper HTML special character escaping.

Affected products

  • MantisBT MantisBT <= 2.28.1

Timeline

  • 2026-04-12: disclosed: Initial report by security researcher siunam
  • 2026-05-09: patched: Fix released in version 2.28.2
  • 2026-05-22: advisory: Public advisory and CVE published

References

Related threats