CVE-2026-3962Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-30)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-07-30: 2Technical Details · 2026-03-12: 1Technical Details · 2026-07-30: 203-1103-1207-30
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-03-121
Disclosure1
2026-07-302
Disclosure2
Full discourse4 posts
  • Geng Yang@geng_zast
    Disclosure

    http://ZAST.AI identified and verified CVE-2026-3962 in Machine-Learning-Web-Apps. User input submitted to POST /preview was reflected back through the template response path. That made a preview feature behave like a real reflected XSS sink. https://t.co/NYUFDsMjqA

    Post summary

    ZAST.AI verified CVE-2026-3962 as a reflected XSS in a machine‑learning web app's preview functionality, providing the core vulnerability details without mention of patches or active exploitation.

    30030290
    48 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: http://ZAST.AI identified and verified CVE-2026-3962 in Machine-Learning-Web-Apps. User input submitted to POST /preview was reflected back through the template response. That created a reflected XSS path. https://t.co/KlzOFdMMVj

    Post summary

    This note announces and confirms CVE-2026-3962 as a reflected XSS issue in Machine‑Learning‑Web‑Apps, describing how user input is reflected but providing no PoC, exploit code, or patch details.

    1000055
    37 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3962 - Jcharis Machine-Learning-Web-Apps Jinja2 Template http://app.py render_template cross site scripting Intel Report: https://ift.tt/lDYUQIT

    Post summary

    An alert raises a potential XSS flaw (CVE‑2026‑3962) in a Jinja2 render_template usage within Jcharis Machine‑Learning‑Web‑Apps, providing technical details but no evidence of a PoC, exploit, active use, patch, or debunking.

    0000029
    342 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3962 A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template… https://www.cve.org/CVERecord?id=CVE-2026-3962

    Post summary

    The text merely reports the existence of CVE-2026-3962 in Jcharis Machine-Learning-Web-Apps, providing minimal technical context but no details on exploitation, patches, or severity.

    0000069
    56.7K followersView on X

Explore more