CVE-2026-55630

Source
https://cve.org/CVERecord?id=CVE-2026-55630
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55630.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55630
Aliases
Published
2026-09-15T15:35:29Z
Modified
2026-09-18T03:30:46Z
Severity
  • 0.0 (None) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N CVSS Calculator
Summary
Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)
Details

Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55630.json"
}
References

Affected packages

Git / github.com/kiwitcms/kiwi

Affected ranges

Type
GIT
Repo
https://github.com/kiwitcms/kiwi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

tcms-api-1.*
tcms-api-1.4.0
tcms-api-1.5.0
tcms-api-1.5.1
tcms-api-4.*
tcms-api-4.0.0
tcms-api-4.2
tcms-api-5.*
tcms-api-5.0
tcms-api-5.1
tcms-api-5.2
tcms-api-5.3
v10.*
v10.0
v10.1
v10.2
v10.3
v10.4
v10.5
v11.*
v11.0
v11.1
v11.2
v11.3
v11.4
v11.5
v11.6
v11.7
v12.*
v12.0
v12.1
v12.2
v12.3
v12.4
v12.5
v12.6
v12.6.1
v12.7
v13.*
v13.0
v13.1
v13.1.1
v13.2
v13.3
v13.4
v13.5
v13.6
v13.7
v14.*
v14.0
v14.1
v14.2
v14.3
v15.*
v15.0
v15.1
v15.2
v15.3
v15.4
v3.*
v3.21.1
v3.21.2
v3.22
v3.23
v3.26
v3.28
v3.30
v3.32
v3.33
v3.37
v3.38
v3.39
v3.41
v3.44
v3.48
v3.49
v3.50
v3.8.18
v3.8.18.21
v4.*
v4.0.0
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.2
v5.*
v5.0
v5.1
v5.2
v5.3
v5.3.1
v6.*
v6.0
v6.0.1
v6.1
v6.1.1
v6.10
v6.11
v6.2
v6.2.1
v6.3
v6.4
v6.5.1
v6.5.2
v6.5.3
v6.6
v6.7
v6.8
v6.9
v7.*
v7.0
v7.1
v7.2
v7.2.1
v7.3
v8.*
v8.0
v8.1
v8.2
v8.3
v8.4
v8.5
v8.6
v8.6.1
v8.7
v8.8
v8.9
v9.*
v9.0
v9.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55630.json"