CVE-2026-27469Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affecting the website and author comment fields. The website field was HTML-escaped using quote=False, which left single and double quotes unescaped. Since the frontend inserts the website value directly into a single-quoted href attribute via string concatenation, a single quote in the URL breaks out of the attribute context, allowing injection of arbitrary event handlers (e.g. onmouseover, onclick). The same escaping is missing entirely from the user-facing comment edit endpoint (PUT /id/) and the moderation edit endpoint (POST /id//edit/). This issue has been patched in commit 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144. To workaround, nabling comment moderation (moderation = enabled = true in isso.cfg) prevents unauthenticated users from publishing comments, raising the bar for exploitation, but it does not fully mitigate the issue since a moderator activating a malicious comment would still expose visitors.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-22); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-22: 102-2202-24
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-02-241
General1
Full discourse2 posts
  • Byambadalai Sumiya@ByamB4
    Disclosure

    CVE-2026-27469 — Stored XSS in isso-comments/isso. Single quote escaping gap in website field leads to script execution via innerHTML injection. https://nvd.nist.gov/vuln/detail/CVE-2026-27469 https://github.com/isso-comments/isso/security/advisories/GHSA-9fww-8cpr-q66r https://t.co/JKDfKFjVDH

    Post summary

    The post announces a stored XSS vulnerability in isso-comments/isso, describing the flaw and linking to the NVD entry and GitHub security advisory.

    00040156
    119 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-27469: Isso... You Have Chosen Death: Analyzing CVE-2026-27469 In the world of self-hosted services, Isso has long been the darling of the static site generation crowd—a lightweight, Python-based commenting server that promised to free us fro... https://cvereports.com/reports/CVE-2026-27469

    Post summary

    The snippet references CVE-2026-27469 but provides no substantive details on exploitation, patches, or technical aspects.

    0000044
    31 followersView on X

Explore more