CVE-2026-7596Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-02: 105-0105-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7596 A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-sy… https://www.cve.org/CVERecord?id=CVE-2026-7596

    Post summary

    The snippet announces CVE-2026-7596, indicating a vulnerability in nextlevelbuilder ui-ux-pro-max-skill version up to 2.5.0 that affects the data.get function, with a reference to the CVE record on cve.org.

    00010266
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7596 Cross Site Scripting in NextLevelBuilder UI-UX-Pro-Max-Skill Up to 2.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7596

    Post summary

    The content announces a new CVE (CVE-2026-7596) describing a Cross Site Scripting vulnerability in NextLevelBuilder UI-UX-Pro-Max-Skill up to version 2.5.0, with no PoC, exploit, or patch details provided.

    0000055
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7596 A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-sy… https://www.cve.org/CVERecord?id=CVE-2026-7596 ----- Traducción: CVE-2026-7596 Se … http://infoflow.cloud`

    Post summary

    The announcement discloses CVE‑2026‑7596 affecting nextlevelbuilder ui‑ux‑pro‑max‑skill up to v2.5.0, highlighting the data.get function in a specific file, but does not provide a PoC, exploit, or patch.

    0000045
    75 followersView on X

Explore more