CVE-2026-79315: XSS

Published Sep 22, 2026
·
Updated

A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the client-side framework evaluates the content as a JavaScript expression. A logged-in panel user who visits a crafted URL allows arbitrary script execution in the same-origin context of the management page, enabling data theft and unauthorized actions through the victim's session.

Affected Software

1 affected component
x-ui=0.3.2

Event History

Sep 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can be targeted by this issue?

A logged-in user of the x-ui management panel can be targeted if they are induced to visit a crafted URL. The resulting script runs in the same-origin context of the management page and can act through that user's session.

2

What does an attacker need to exploit it?

The attacker needs to craft a malicious request URI and cause an authenticated management-panel user to open it. The available information does not indicate that the attacker needs an existing panel account.

3

Are server-side HTML escaping controls sufficient mitigation?

No. The issue occurs because browser entity decoding happens before the client-side framework evaluates the reflected value as a JavaScript expression, rendering server-side HTML entity escaping ineffective in this template-binding context.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203