CVE-2026-39416: Circl Ail Framework
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned without an explicit text/plain content type, allowing the browser to interpret the response as active HTML. This could result in execution of arbitrary JavaScript in the context of an authenticated user viewing a crafted item. This vulnerability is fixed in 6.8.
Affected products
- Circl Ail Framework: up to and including 6.7
Published 2026-04-08. Last modified 2026-07-24.