CVE-2026-66824 - Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding
CVE ID :CVE-2026-66824
Published : July 27, 2026, 9:17 p.m. | 1 hour, 34 minutes ago
Description :A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured and potentially attacker-controlled web content, a specially crafted value could prematurely terminate the surrounding
Published : July 27, 2026, 9:17 p.m. | 1 hour, 34 minutes ago
Description :A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured and potentially attacker-controlled web content, a specially crafted value could prematurely terminate the surrounding