CVE-2026-27169Disclosure(opensift / opensift)

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to XSS. Stored content can execute JavaScript when later viewed in authenticated sessions. An attacker who can influence stored study/quiz/flashcard content could trigger script execution in a victim’s browser, potentially performing actions as that user in the local app session. This issue has been fixed in version 1.1.3-alpha.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opensift

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
opensift

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-21: 1Technical Details · 2026-02-21: 102-21
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27169** pertains to a Cross-Site Scripting (XSS) vulnerability in **OpenSift**, an AI-powered study tool that handles large datasets with features like semantic search and generative AI. The vulnerability exists in versions **1.1.2-alpha and below**, where untrusted user-generated or model-generated content is rendered in the chat UI using unsafe HTML interpolation patterns. This flaw allows malicious actors to inject and execute arbitrary JavaScript code within the context of an authenticated user session, leading to potential security breaches. #Cybersecurity #CVE #HighSeverity #SecurityAlert #XSS https://cvetodo.com/cve/CVE-2026-27169

    Post summary

    A new XSS vulnerability (CVE‑2026‑27169) has been disclosed in OpenSift 1.1.2‑alpha and older, allowing malicious JavaScript injection via unsafe rendering of untrusted content; no PoC, exploit tool, or patch details are provided.

    0000035
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensiftopensift-python-

Explore more