CVE-2026-55630
Description
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kiwitcmsPyPI | <= 12.4 | — |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-473p-56xx-vg67ghsaADVISORY
- github.com/kiwitcms/Kiwi/releases/tag/v16.1nvdWEB
- github.com/kiwitcms/Kiwi/security/advisories/GHSA-473p-56xx-vg67nvdWEB
- kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161ghsaWEB
- github.com/kiwitcms/Kiwi/commit/1c2ecc8485faeefd84a526314a0a60d132fbbc09nvd
- github.com/kiwitcms/Kiwi/commit/d5d36e74cf9333cb37e3a8743b22b74dfa9a0139nvd
News mentions
0No linked articles in our index yet.