CVE-2026-76203

Source
https://cve.org/CVERecord?id=CVE-2026-76203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76203
Published
2026-08-19T14:23:17.894Z
Modified
2026-08-21T03:47:07.804410986Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
Details

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via CSS hex escapes that reconstruct the url() function and evade the sanitizer blocklist

Database specific
{
    "cna_assigner": "Secur0",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76203.json",
    "cwe_ids": [
        "CWE-180"
    ]
}
References

Affected packages

Git / github.com/ccyl13/pentestify

Affected ranges

Type
GIT
Repo
https://github.com/ccyl13/pentestify
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.2.0"
        },
        {
            "fixed": "1ed1aad"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76203.json"