VYPR
Unrated severityNVD Advisory· Published Aug 5, 2021· Updated Aug 4, 2024

CVE-2021-38138

CVE-2021-38138

Description

OneNav beta 0.9.12 is vulnerable to stored XSS via the Add Link feature, as the application lacks XSS filtering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OneNav beta 0.9.12 is vulnerable to stored XSS via the Add Link feature, as the application lacks XSS filtering.

Vulnerability

OneNav beta 0.9.12 contains a stored cross-site scripting (XSS) vulnerability in the Add Link feature. The application does not sanitize user input when adding a link, allowing arbitrary JavaScript to be injected. This affects version 0.9.12 and potentially earlier versions. [1]

Exploitation

An attacker with the ability to add links (requires a user account with link creation privileges) can inject malicious HTML or JavaScript into the link name or URL fields. If the link is displayed to other users, the payload executes in their browsers. No special network position is required beyond normal application access. [1]

Impact

Successful exploitation leads to arbitrary JavaScript execution in the context of the victim's session. This can result in session hijacking, data theft, or further attacks against the application. The vendor notes that the risk is largely limited to compromised accounts, but XSS can propagate to other users who view the malicious link. [1]

Mitigation

No official patch or fix has been released as of the publication date. The vendor plans to add XSS protection in a future release. Users may consider disabling the Add Link feature or implementing a web application firewall (WAF) rule to block XSS payloads. The latest release at the time of writing is version 1.2.4 [2], but it is unclear if XSS protection has been added. It is recommended to update to the latest version and test for XSS protection. [2]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • OneNav/OneNavdescription
  • Helloxz/Onenavllm-fuzzy
    Range: = 0.9.12 beta

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.