Junglewise Threat Intelligence

CVE-2026-42558: Xibo CMS stored XSS and iframe sandbox escape in Data Connector

CVE-2026-42558 · Severity: high · CVSS 7.6 · Published 2026-06-10

Executive brief

Xibo is an open-source digital signage platform used to manage content on public displays and screens. A security flaw in the content management system allows certain authorized users to bypass security restrictions and execute malicious scripts. If exploited, an attacker could gain unauthorized access to sensitive information or perform actions on behalf of other users, potentially compromising the integrity of the signage network.

Technical details

A vulnerability chain in Xibo CMS prior to version 4.4.2 involves a stored Cross-Site Scripting (XSS) flaw and an iframe sandbox escape. The issue resides in the Data Connector functionality within the DataSet component. An attacker with 'Add DataSet' privileges can craft malicious messages that escape the intended iframe sandbox, leading to XSS. While the attack requires low-level authenticated privileges and user interaction, the 'Scope' is changed (CVSS S:C) because the script execution can impact the broader CMS application beyond the restricted iframe. The vulnerability is addressed in version 4.4.2.

Affected products

  • Xibo Signage Xibo CMS < 4.4.2

Timeline

  • 2026-04-18: disclosed: Responsible disclosure by 0xRIXET
  • 2026-04-20: patched: Fix PR produced and tested
  • 2026-04-22: other: Fix available in a release
  • 2026-05-22: advisory: Public disclosure of GHSA-6389-j56c-9fww
  • 2026-06-10: other: CVE-2026-42558 published

References