CVE-2026-90567: quequnlong shiyi-blog Search index.vue highlightKeyword cross site scripting
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
The issue affects quequnlong shiyi-blog versions up to and including 1.2.1 where the Search component's highlightKeyword function processes title or summary values.
What does exploitation require?
The attack can be initiated remotely, but the supplied severity vector indicates the attacker needs low privileges and user interaction is required. The vulnerable inputs are the title and summary arguments handled by the search highlighting functionality.