{"id":"CVE-2026-27469","summary":"Isso: Stored XSS via comment website field","details":"Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affecting the website and author comment fields. The website field was HTML-escaped using quote=False, which left single and double quotes unescaped. Since the frontend inserts the website value directly into a single-quoted href attribute via string concatenation, a single quote in the URL breaks out of the attribute context, allowing injection of arbitrary event handlers (e.g. onmouseover, onclick). The same escaping is missing entirely from the user-facing comment edit endpoint (PUT /id/) and the moderation edit endpoint (POST /id//edit/). This issue has been patched in commit 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144. To workaround, nabling comment moderation (moderation = enabled = true in isso.cfg) prevents unauthenticated users from publishing comments, raising the bar for exploitation, but it does not fully mitigate the issue since a moderator activating a malicious comment would still expose visitors.","aliases":["GHSA-9fww-8cpr-q66r","PYSEC-2026-2527"],"modified":"2026-08-12T03:51:43.462777223Z","published":"2026-02-21T07:24:38.971Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27469.json","unresolved_ranges":[{"extracted_events":[{"fixed":"0afbfe0691ee237963e8fb0b2ee01c9e55ca2144"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"0afbfe0691ee237963e8fb0b2ee01c9e55ca2144"}],"source":"DESCRIPTION"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-79"]},"references":[{"type":"WEB","url":"https://docs.python.org/3/library/html.html#html.escape"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27469.json"},{"type":"ADVISORY","url":"https://github.com/isso-comments/isso/security/advisories/GHSA-9fww-8cpr-q66r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27469"},{"type":"FIX","url":"https://github.com/isso-comments/isso/commit/0afbfe0691ee237963e8fb0b2ee01c9e55ca2144"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/isso-comments/isso","events":[{"introduced":"0"},{"fixed":"0afbfe0691ee237963e8fb0b2ee01c9e55ca2144"}],"database_specific":{"source":"REFERENCES"}}],"versions":["0.13.1.dev0","0.13.0","0.12.6-pre","0.12.6","0.12.5","0.12.4","0.12.2","0.12.1","0.12.0","0.11.1","0.11.0","upstream/0.10.6+git20170928","0.10.6","0.10.5","upstream/0.10.4","0.10.4","0.10.3","0.10.2","0.10.1","0.10","0.9","0.8","0.7","0.5","0.4","0.3","0.2.1","0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27469.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}