Junglewise Threat Intelligence

CVE-2026-5577: Song-Li cross_browser SQL injection in details endpoint

CVE-2026-5577 · Severity: high · CVSS 7.3 · Published 2026-04-05

Executive brief

Song-Li cross_browser is a tool used for browser fingerprinting and identification. A security flaw in its legacy database component allows remote attackers to bypass security controls and access sensitive fingerprint data stored in the database. This could lead to the exposure of user tracking information and potentially disrupt the service's operations.

Technical details

A SQL injection vulnerability exists in the legacy MySQL-backed Flask application of Song-Li cross_browser. The vulnerability is located in the `/details` endpoint within `flask/uniquemachine_app.py`. The application retrieves the `ID` parameter from a JSON request body and directly concatenates it into a SQL SELECT statement without parameterization or escaping. A remote, unauthenticated attacker can exploit this by sending a crafted JSON payload (e.g., using `' OR 1=1 #`) to the endpoint. This allows for unauthorized data retrieval from the `features` table and potentially broader database exfiltration depending on the MySQL configuration. No patch is currently available as the vendor did not respond, but users are advised to avoid deploying the legacy `uniquemachine_app.py` component.

Affected products

  • Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a

Timeline

  • 2022-01-17: other: Last confirmed affected commit (ca690f0)
  • 2026-03-20: disclosed: Vulnerability reported by researcher Winegee
  • 2026-04-05: advisory: Initial disclosure via VulDB/NVD

References