Executive brief
SOY Gallery is a web-based image gallery management application. The vulnerability allows an attacker to inject and execute arbitrary JavaScript code in the web browser of users logging into the system, potentially allowing theft of session credentials or other malicious actions performed on behalf of the logged-in user.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in SOY Gallery version 2.0.0 and earlier. The vulnerability requires an authenticated attacker (login credentials required) and user interaction (the victim must be logging in), but no special network access or elevated privileges are needed. An attacker can inject malicious JavaScript that executes in the context of the affected user's browser session, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability was patched in version 2.1.0, released on 2026-08-31.
Affected products
- Tsuyoshi Saito SOY Gallery 2.0.0 and earlier
Timeline
- 2026-08-28: disclosed
- 2026-08-31: patched: Version 2.1.0 released