{"id":"CVE-2026-42548","aliases":["GHSA-fcx8-ph5r-mxr4"],"url":"https://o3.security/vulnerability/CVE-2026-42548","summary":"Flight: Reflected XSS via unvalidated JSONP callback in Flight::jsonp()","details":"Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query parameter directly into an application/javascript response body without validating that the value is a legal JavaScript identifier. An attacker can inject arbitrary JavaScript that executes in the response origin, enabling reflected cross-site scripting. This vulnerability is fixed in 3.18.1.","published":"2026-05-13T19:21:44.125Z","modified":"2026-08-07T11:31:14.202184004Z","cvss":null,"epss":{"score":0.00341,"percentile":0.26806,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"flightphp/core","fixedVersion":"3.18.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42548.json"},{"type":"ADVISORY","url":"https://github.com/flightphp/core/security/advisories/GHSA-fcx8-ph5r-mxr4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42548"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:14.202184004Z"}}