VYPR
High severity8.7NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-41031

CVE-2026-41031

Description

Stored XSS in Vinna Process Monitor allows low-privilege authenticated users to steal admin tokens by injecting JavaScript into media imports.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Vinna Process Monitor allows low-privilege authenticated users to steal admin tokens by injecting JavaScript into media imports.

Vulnerability

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Media import functionality of Vinna Process Monitor. Versions 3.1.0 through 3.1.4 and 4.0.0 through 4.0.6 are affected. An authenticated user can inject malicious JavaScript code into the application via the media import feature [1].

Exploitation

An attacker must first be authenticated to the application and have low privileges. They can then upload a malicious HTML file containing JavaScript to the Media import feature. The vulnerability is triggered when an administrator opens a link to this file, causing the embedded JavaScript to execute without the administrator's knowledge [1].

Impact

Successful exploitation allows an attacker to steal administrative access tokens and session credentials, specifically the administrator's Bearer token from browser storage. This grants the attacker full application access with administrative privileges [1].

Mitigation

Vinna Process Monitor version 4.0.7 and later, and version 3.1.5 and later, are fixed. Users are recommended to upgrade to version 4.0.7 or later. For users on the 3.1.x branch who cannot upgrade immediately, workarounds include restricting network access to Process Monitor to only the corporate network and educating users not to click links to Process Monitor from untrusted sources until version 3.1.8 is released in September 2026 [1].

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.