
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27469 is a stored Cross-Site Scripting (XSS) vulnerability in Isso, a lightweight commenting server written in Python and JavaScript, affecting versions prior to 0.13.2. The flaw exists in the website and author comment fields, where insufficient HTML escaping allows attackers to inject arbitrary JavaScript event handlers that persist in the database and execute in every visitor's browser. It was reported by researcher ByamB4, published on February 20–21, 2026, and patched in commit 0afbfe0 (released as version 0.13.2). It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Isso Security Advisory).
The root cause is improper output encoding (CWE-116) leading to stored XSS (CWE-79). The website field was sanitized using Python's html.escape() with quote=False, which leaves single and double quotes unescaped. Because the frontend inserts the website value directly into a single-quoted href attribute via string concatenation, a single quote in the attacker-supplied URL breaks out of the attribute context, enabling injection of arbitrary event handlers such as onmouseover or onclick. Critically, escaping was entirely absent from the user-facing comment edit endpoint (PUT /id/) and the moderation edit endpoint (POST /id/<key>/edit/), widening the attack surface. The fix applies html.escape(..., quote=True) to the website field across all three write paths (GitHub Commit, Isso Security Advisory).
Any visitor to a page embedding Isso comments is at risk. Because moderation is disabled by default, an unauthenticated attacker can post a malicious comment anonymously; the payload persists in the database and fires on every subsequent page load. Using a full-page invisible overlay technique, the payload can be triggered by mere mouse movement, requiring no deliberate user interaction beyond visiting the page. Successful exploitation can lead to credential theft, session hijacking, and unauthorized actions performed on behalf of victims in the context of the affected site (GitHub Advisory, Isso Security Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Feedly). The EPSS score is approximately 0.06–0.108%, placing it in the 29th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication and minimal user interaction (mouse movement over the page), making it low-complexity once a malicious comment is posted (GitHub Advisory).
href attribute context, e.g., http://x.com/?'onmouseover='alert(document.domain)'x='.POST /new?uri=/target-page/ request with a JSON body containing the crafted website field and any valid text value. No authentication is required.<a href='http://x.com/?'onmouseover='alert(document.domain)'x=''>.POST /new or PUT /id/ requests to the Isso API containing website field values with single quotes, event handler keywords (onmouseover, onclick, onerror), or JavaScript URIs (javascript:).website values containing URL-encoded or raw single quotes followed by HTML event handler strings; repeated requests to /id/<id>/edit/<key> with suspicious JSON payloads.comments.db) containing website or author field values with unescaped single quotes, event handler attributes, or <script> tags in stored comment records.<a> elements.Upgrade Isso to version 0.13.2 or later, which includes the fix from commit 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144 applying html.escape(..., quote=True) to the website field across all write paths. As a partial workaround, enable comment moderation in isso.cfg (moderation = enabled = true) to prevent unauthenticated users from directly publishing comments; however, this does not fully mitigate the risk since a moderator approving a malicious comment would still expose site visitors. There is no configuration-only workaround that fully prevents the vulnerability (GitHub Advisory, Isso Security Advisory).
The vulnerability was reported by security researcher ByamB4 and coordinated by jelmer (an Isso maintainer), with the advisory published on February 20, 2026. A technical write-up was published on dev.to analyzing the vulnerability in detail. Coverage appeared across vulnerability aggregators including CIRCL, Vulners, and VulDB shortly after disclosure, indicating moderate community interest. No major vendor statements or widespread media coverage beyond standard vulnerability tracking have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."