A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 mitigates this issue. The identifier of the patch is c87682afa8df79853299f75489c9d333f7bc5fce. It is suggested to upgrade the affected component.
{
"cwe_ids": [
"CWE-79",
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10514.json",
"cna_assigner": "VulDB"
}{
"extracted_events": [
{
"introduced": "1.6.0"
},
{
"last_affected": "1.6.0"
},
{
"introduced": "1.6.1"
},
{
"last_affected": "1.6.1"
},
{
"introduced": "1.6.2"
},
{
"last_affected": "1.6.2"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"2026-08-12T16:24:45Z"
[
{
"id": "CVE-2026-10514-227a04e8",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 445.0,
"function_hash": "268531600353582151246163503309634825220"
},
"source": "https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce",
"target": {
"function": "jackson2ObjectMapperBuilderCustomizer",
"file": "backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java"
}
},
{
"id": "CVE-2026-10514-397b0773",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"39552555681519819189387037147769905448",
"251350195022106776886983067754661369744",
"45965048041040821694741255665393844153",
"94088371098056002821887869311948844183",
"254217025449220859722682014440749943913",
"323008323022811874092129056145067138141",
"44740514636723159633753781099826715128",
"61015434603556391711679583573628900240",
"333359280892804067620328767926291344950",
"265747610839340378484334957327677708931",
"58942325475207396321884924536250483554",
"282540525393533944297597144681895919237",
"313269510097358807310163056520956022181",
"225287783429731489671799643383219004463",
"32275434953731262630553471914023117618",
"265324251289332916155890401412783687713",
"18744409616202217698160852359591471275",
"132032598730935277598957983897534133274",
"90615326069007838700628674204908993936",
"159672745212706670003682564031355154174",
"173094764080546024817732512974621693650",
"271996939658003306207925676943741337696",
"289836497241667484882103762303030004200",
"297696124579921608161803891376881595536",
"145375660899068647807428379536872032926",
"213588714927290895947412294745517159155",
"36754399147974256052504292066187255475",
"115446728591475414005609566895079038815",
"184640788286126623453364494726640844626",
"234140577270823758213366940469681269739"
]
},
"source": "https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce",
"target": {
"file": "backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java"
}
},
{
"id": "CVE-2026-10514-a5718b56",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"300057984841402190454347434645157421473",
"220282082689875518599067250696579483920"
]
},
"source": "https://github.com/1panel-dev/cordyscrm/commit/7c2eadb9d76cc6613e6ccc7089c1c2f77480ecad",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/mapper/ExtApprovalInstanceMapper.java"
}
},
{
"id": "CVE-2026-10514-cff5f585",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"264654641498068565163148758720303247925",
"326319180140202264514769382317587271969",
"207053217838931752325967036852955105498",
"49388233016336645149709755269713248646",
"155526835061659021775855202167188289841",
"118485121350428657810771187351667871175",
"250469855315514493926495268485789081327",
"152047592666521901160313551738195476006",
"85252776332415329353061921149240507081",
"262604562922142974165366710064216355354",
"262475088046163131975242340744163792859",
"306657523969764582489273493365329137111",
"191712704461071390710765108468701459976",
"323168859459042983681696155917142195420",
"205956062299661666358570989598739035348"
]
},
"source": "https://github.com/1panel-dev/cordyscrm/commit/7c2eadb9d76cc6613e6ccc7089c1c2f77480ecad",
"target": {
"file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalActionService.java"
}
},
{
"id": "CVE-2026-10514-d681b7ec",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 198.0,
"function_hash": "172719391140758691532530812452954467540"
},
"source": "https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce",
"target": {
"function": "deserialize",
"file": "backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10514.json"