Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ail-framework

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

AIL Framework versions before 7.0 contain a server-side request forgery (SSRF) vulnerability in the crawler submission feature. Authenticated users with low privileges can submit arbitrary URLs for crawling without sufficient validation, allowing requests to internal or restricted network addresses. This includes localhost, private IP ranges, link-local addresses, and cloud metadata services. The vulnerability enables attackers to use the server as a pivot to access internal services and retrieve sensitive data such as HTML content, screenshots, and HAR data. A patch has been introduced to validate and reject URLs resolving to non-global IP addresses, mitigating this risk.

Join the discussion

AIL Project's ail-framework contains a stored cross-site scripting (XSS) vulnerability in the translation controls for chat messages and forum posts. The vulnerability arises because message and post identifiers are inserted directly into inline JavaScript onclick handlers without proper encoding for JavaScript string literals. This allows an attacker to inject arbitrary JavaScript code if a specially crafted identifier is used. Exploitation requires a victim to click the affected translation button, causing the injected script to execute in the victim's browser under the AIL instance's security context.

Join the discussion

AIL Framework versions up to 7.0.0 contain a stored cross-site scripting (XSS) vulnerability in the crawler domain view. This flaw allows an attacker to inject malicious JavaScript into stored URLs that are later embedded unsafely into a JavaScript onclick handler. Exploitation requires an authenticated analyst to interact with the malicious screenshot entry, potentially enabling session information access or unauthorized actions within the application context. The vulnerability is due to improper input neutralization and was fixed by applying Jinja's tojson filter to safely escape the URL before insertion.

Join the discussion

AIL Framework versions up to 7.0.0 contain a reflected cross-site scripting (XSS) vulnerability in the /tag/add_tags endpoint. The vulnerability occurs because error messages include attacker-controlled input directly in HTML responses without proper encoding. Exploitation requires an authenticated user to interact with a crafted link, potentially allowing execution of arbitrary JavaScript in the victim's browser within the application's security context. This could enable actions such as session hijacking or data modification based on the victim's privileges.

Join the discussion

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF directory.

Join the discussion

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot storage directories. This may allow the attacker to download and read arbitrary files that are accessible to the AIL process. The issue occurs because user-controlled path components were joined with application storage paths without verifying that the resolved path remained within the expected directory. The affected download functionality could then include the contents of such files in a generated archive.

Join the discussion

AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects. An authenticated AIL user could craft malicious item identifiers containing path traversal sequences to cause the application to read gzip-compressed files accessible to the AIL process. This could result in unauthorized disclosure of local file contents, limited to files readable by the application and compatible with the expected gzip-compressed item format. The issue was fixed by validating that both requested items exist before their contents are accessed.

Join the discussion

A stored cross-site scripting (XSS) vulnerability exists in ail-framework versions prior to 6.8. The issue occurs in the modal item preview functionality when processing item content longer than 800 characters. Attacker-controlled content is returned without an explicit text/plain content type, allowing browsers to interpret it as active HTML and execute arbitrary JavaScript in the context of an authenticated user. This vulnerability has a high severity score of 8.5 and is fixed in version 6.8.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/ail-framework
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses