CVE Explorer
CVE-2026-27605
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the application allows uploading files (project logos) without validating the file type or content. It trusts the extension provided by the user. These files are saved to the uploads/ directory and served statically. An attacker can upload an HTML file containing malicious JavaScript. Since authentication tokens are likely stored in localStorage (
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"chartbrew","vendor":"chartbrew","versions":[{"status":"affected","version":"< 4.8.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/chartbrew/chartbrew/releases/tag/v4.8.4","tags":["x_refsource_MISC"],"url":"https://github.com/chartbrew/chartbrew/releases/tag/v4.8.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/references/1
{"name":"https://github.com/chartbrew/chartbrew/security/advisories/GHSA-jf6m-hm53-c364","tags":["x_refsource_CONFIRM"],"url":"https://github.com/chartbrew/chartbrew/security/advisories/GHSA-jf6m-hm53-c364"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:46389cfc5ab6b1f80539508c6b16a30c2f9ad6a96e887772f19277632e256ecf · sha256:e73dcedcf84b9c3a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.