CVE Explorer
CVE-2026-1466
Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents could be exploited for cross site scripting. This was done by storing the MIME type of a file and allowing only browser preview for MIME types beginning with image (except for image/svg+xml, see CVE-2022-30110, CVE-2024-12326 and CVE-2025-7066), video and audio. However, it was possible to bypass this check by sending a manipulated HTTP request with an invalid MIME type like i
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Jirafeau","vendor":"Jirafeau project","versions":[{"lessThan":"4.7.1","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://gitlab.com/jirafeau/Jirafeau/-/commit/747afb20bfcff14bb67e40e7035d47a6311ba3e1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/references/0
{"url":"https://www.cve.org/CVERecord?id=CVE-2022-30110"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/references/1
{"url":"https://www.cve.org/CVERecord?id=CVE-2024-12326"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/references/2
{"url":"https://www.cve.org/CVERecord?id=CVE-2025-7066"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4865af4112d9393fc775d9ac7cdb60abed0a0a404a2701b93e18a6b5399665e3 · sha256:6b96c11f2f12f6a8… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.