The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluge" }, { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluge-common" }, { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluge-console" }, { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluge-gtk" }, { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluge-web" }, { "binary_version": "2.1.2~dev0+20240219-1", "binary_name": "deluged" } ] }