
🚨*CVE* CVE-2026-3673 An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered.… https://www.cve.org/CVERecord?id=CVE-2026-3673 ----- Traducción: CVE-2026-3673 Un … http://infoflow.cloud`
Post summary
The tweet announces CVE-2026-3673 and briefly describes how an authenticated attacker can inject a malicious tag to execute JavaScript, but provides no PoC, exploit code, or patch info.


