{"id":"GHSA-cpm7-cfpx-3hvp","summary":"Emissary has Stored XSS via Navigation Template Link Injection","details":"## Summary\n\nMustache navigation templates interpolated configuration-controlled link values\ndirectly into `href` attributes without URL scheme validation. An administrator\nwho could modify the `navItems` configuration could inject `javascript:` URIs,\nenabling stored cross-site scripting (XSS) against other authenticated users\nviewing the Emissary web interface.\n\n## Details\n\n### Vulnerable code — `nav.mustache` (line 10)\n\n```html\n{{#navItems}}\n\u003cli class=\"nav-item\"\u003e\n  \u003ca class=\"nav-link\" href=\"{{link}}\"\u003e{{display}}\u003c/a\u003e\n\u003c/li\u003e\n{{/navItems}}\n```\n\nThe `{{link}}` value was rendered without any scheme validation. Mustache's\ndefault HTML escaping protects against injection of new HTML tags but does\n**not** prevent `javascript:` URIs in `href` attributes, since `javascript:`\ncontains no characters that HTML-escaping would alter.\n\n### Attack vector\n\nAn administrator sets a navigation item's link to:\n```\njavascript:alert(document.cookie)\n```\n\nAny authenticated user who clicks the navigation link executes the script in\ntheir browser context.\n\n### Impact\n\n- Session hijacking via cookie theft\n- Actions performed on behalf of the victim user\n- Requires administrative access to modify navigation configuration\n- Requires user interaction (clicking the malicious link)\n\n### Mitigating factors\n\n- Exploitation requires administrative access to modify the `navItems`\n  configuration\n- User interaction (clicking the link) is required\n- The Emissary web interface is typically accessed only by authenticated\n  operators within a trusted network\n\n## Remediation\n\nFixed in [PR #1293](https://github.com/NationalSecurityAgency/emissary/pull/1293),\nmerged into release 8.39.0.\n\n### Server-side link validation — `NavAction.java`\n\nAn allowlist regex was added that only permits `http://`, `https://`, or\nsite-relative (`/`) URLs:\n\n```java\nprivate static final Pattern VALID_LINK = Pattern.compile(\"^(https?:/)?/.*\");\n\nprivate static boolean isValidLink(String link) {\n    if (!VALID_LINK.matcher(link).matches()) {\n        logger.warn(\"Skipping invalid navigation link '{}'\", link);\n        return false;\n    }\n    return true;\n}\n```\n\nInvalid links are logged and silently dropped from the rendered navigation.\n\n### Template hardening — `nav.mustache`\n\nAdded `rel=\"noopener noreferrer\"` to all navigation link anchor tags as a\ndefense-in-depth measure:\n\n```html\n\u003ca class=\"nav-link\" href=\"{{link}}\" rel=\"noopener noreferrer\"\u003e{{display}}\u003c/a\u003e\n```\n\nTests were added to verify that `javascript:` and `ftp://` URIs are rejected\nwhile `http://`, `https://`, and site-relative (`/path`) links are accepted.\n\n## Workarounds\n\nIf upgrading is not immediately possible, audit the navigation configuration\nto ensure all `navItems` link values use only `http://`, `https://`, or\nrelative (`/`) URL schemes.\n\n## References\n\n- [PR #1293 — validate nav links](https://github.com/NationalSecurityAgency/emissary/pull/1293)\n- Original report: GHSA-wjqm-p579-x3ww","aliases":["CVE-2026-35571"],"modified":"2026-04-07T20:41:25.005181Z","published":"2026-04-07T20:17:14Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-07T20:17:14Z","nvd_published_at":"2026-04-07T16:16:29Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/NationalSecurityAgency/emissary/security/advisories/GHSA-cpm7-cfpx-3hvp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35571"},{"type":"WEB","url":"https://github.com/NationalSecurityAgency/emissary/pull/1293"},{"type":"WEB","url":"https://github.com/NationalSecurityAgency/emissary/commit/e2078417464b9004620dde28dcbca2f73ea06c13"},{"type":"PACKAGE","url":"https://github.com/NationalSecurityAgency/emissary"}],"affected":[{"package":{"name":"gov.nsa.emissary:emissary","ecosystem":"Maven","purl":"pkg:maven/gov.nsa.emissary/emissary"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.39.0"}]}],"versions":["8.0.0","8.1.0","8.10.0","8.11.0","8.11.1","8.12.0","8.13.0","8.14.0","8.15.0","8.16.0","8.17.0","8.18.0","8.19.0","8.19.1","8.2.0","8.20.0","8.21.0","8.22.0","8.23.0","8.24.0","8.25.0","8.26.0","8.27.0","8.28.0","8.29.0","8.3.0","8.30.0","8.31.0","8.32.0","8.33.0","8.34.0","8.35.0","8.36.0","8.37.0","8.38.0","8.4.0","8.5.0","8.6.0","8.7.0","8.7.1","8.8.0","8.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 8.38.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cpm7-cfpx-3hvp/GHSA-cpm7-cfpx-3hvp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}