{"id":"CVE-2026-23695","aliases":["GHSA-ch4j-vcf5-58x5"],"url":"https://o3.security/vulnerability/CVE-2026-23695","summary":"Cockpit CMS 2.14.0 Stored XSS via Set Field Display Template","details":"Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items list.","published":"2026-05-15T16:33:46.897Z","modified":"2026-08-12T03:51:34.461340402Z","cvss":null,"epss":{"score":0.00138,"percentile":0.03626,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cockpit-hq/cockpit","fixedVersion":null}],"fix":{"url":"https://github.com/Cockpit-HQ/Cockpit/commit/72a83fcfe85ad8330e9ae834bc02fa517b5749e9","label":"Cockpit-HQ/Cockpit@72a83fc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23695.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23695"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cockpit-cms-stored-xss-via-set-field-display-template"},{"type":"FIX","url":"https://github.com/Cockpit-HQ/Cockpit/commit/72a83fcfe85ad8330e9ae834bc02fa517b5749e9"},{"type":"PACKAGE","url":"https://github.com/Cockpit-HQ/Cockpit"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.461340402Z"}}