CVE-2026-45228

Source
https://cve.org/CVERecord?id=CVE-2026-45228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45228
Published
2026-05-13T19:54:40.534Z
Modified
2026-08-04T11:51:00.615054067Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Quark Drive (quark-auto-save) < 0.8.5 Stored XSS via System Configuration
Details

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the POST /update endpoint, which are persisted to disk and executed in the browsers of all authenticated users accessing the System Configuration tab, allowing session cookie exfiltration and arbitrary authenticated actions.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45228.json"
}
References

Affected packages

Git / github.com/cp0204/quark-auto-save

Affected ranges

Type
GIT
Repo
https://github.com/cp0204/quark-auto-save
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.8.5"
        }
    ]
}

Affected versions

v0.*
v0.2.1
v0.2.10
v0.2.10.1
v0.2.11
v0.2.11.1
v0.2.12
v0.2.13
v0.2.14
v0.2.2
v0.2.3
v0.2.4
v0.2.4.1
v0.2.5
v0.2.5.1
v0.2.5.2
v0.2.6
v0.2.6.1
v0.2.7
v0.2.7.1
v0.2.7.2
v0.2.7.3
v0.2.8
v0.2.8.1
v0.2.9
v0.2.9.1
v0.2.9.10
v0.2.9.2
v0.2.9.3
v0.2.9.4
v0.2.9.5
v0.2.9.6
v0.2.9.7
v0.2.9.8
v0.2.9.9
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.6.1
v0.3.7
v0.3.8
v0.3.8.1
v0.3.9
v0.3.9.1
v0.3.9.2
v0.3.9.3
v0.3.9.4
v0.3.9.5
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.3.1
v0.5.4
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45228.json"