CVE Explorer
CVE-2026-32822
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any unauthenticated attacker can place arbitrary HTML into flash notifications on public routes and rely on the frontend toast component to inject that content into the DOM with `innerHTML`. This creates a reflected DOM XSS that can be delivered with a crafted link to a p
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"dataCycle-CORE","vendor":"datacycle-engine","versions":[{"status":"affected","version":"<= 25.07.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b3a7c0544271523d15f72f204c501bfa24e85ab39919d1559f73d1e88d0cc17b · sha256:872b3a40dde86d64… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b3a7c0544271523d15f72f204c501bfa24e85ab39919d1559f73d1e88d0cc17b · sha256:872b3a40dde86d64… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-80","description":"CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b3a7c0544271523d15f72f204c501bfa24e85ab39919d1559f73d1e88d0cc17b · sha256:872b3a40dde86d64… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-q6x5-wcg6-v4gw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-q6x5-wcg6-v4gw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3a7c0544271523d15f72f204c501bfa24e85ab39919d1559f73d1e88d0cc17b · sha256:872b3a40dde86d64… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.