Junglewise Threat Intelligence

CVE-2026-5385: GLPI stored XSS in knowledge base

CVE-2026-5385 · Severity: info · CVSS 8.4 · Published 2026-06-02

Technologies: GLPI Project GLPI. Vendors: GLPI Project.

Executive brief

GLPI is an open-source IT asset and service desk management platform. A security vulnerability in its knowledge base component allows users with write access to inject malicious scripts into articles. When other users, such as IT administrators or employees, view these articles, the scripts execute in their browser, potentially leading to unauthorized data access or account takeover.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GLPI's knowledge base component due to improper neutralization of input during web page generation (CWE-79). An attacker with high privileges (specifically write access to the knowledge base) can store a malicious JavaScript payload within a knowledge base item. The attack is triggered when another user views the affected item, requiring administrative or user interaction. Successful exploitation can lead to a full compromise of the victim's session, allowing for unauthorized data exfiltration or modification within the GLPI environment. The issue is resolved in version 11.0.7.

Affected products

  • glpi-project GLPI >= 11.0.0, < 11.0.7

Timeline

  • 2026-04-29: patched: Version 11.0.7 released
  • 2026-06-01: advisory: GitHub Security Advisory published
  • 2026-06-02: disclosed: NVD publication date

References