Junglewise Threat Intelligence

CVE-2026-45231: DumbWareio DumbAssets stored XSS in asset fields

CVE-2026-45231 · Severity: medium · CVSS 6.1 · Published 2026-05-18

Executive brief

DumbAssets, an asset management application, is vulnerable to a security flaw where malicious code can be hidden within asset details like names, descriptions, or serial numbers. If an attacker saves an asset with a malicious payload, that code will execute in the browser of any user who later views the asset list. This could allow an attacker to steal user session information, perform actions on behalf of other users, or potentially access internal network services if security headers are not properly configured.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in DumbAssets versions up to and including 1.0.11. The root cause is a failure to perform server-side sanitization on asset fields (including name, description, modelNumber, serialNumber, and tags) combined with the use of 'innerHTML' to render these fields on the client side without escaping. An attacker can exploit this by submitting malicious HTML or JavaScript payloads via the asset API endpoints. When an administrative user or another viewer accesses the asset list or dashboard, the payload executes in their browser context. If a Content Security Policy (CSP) is absent or weak, the script can further be used to pivot and make unauthorized requests to internal network services. A patch has been proposed in pull request #135 which introduces a centralized escaping utility.

Affected products

  • DumbWareio DumbAssets through 1.0.11

Timeline

  • 2026-05-16: patched: Pull request #135 submitted to fix the vulnerability
  • 2026-05-18: advisory: CVE-2026-45231 published

References

Related threats