{"id":"CVE-2026-82396","aliases":["GHSA-pp4x-ccxq-6r33"],"url":"https://o3.security/vulnerability/CVE-2026-82396","summary":"Sulu: Stored XSS via media download inline-disposition override","details":"Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the inline query parameter for scriptable MIME types. The vulnerable stored Content-Type values include text/html, application/xhtml+xml, text/xml, and application/xml. An attacker with media upload permission can store an HTML, XHTML, or XML document and create a link using inline=1, causing the application to return the file on the Sulu origin instead of forcing Content-Disposition attachment. When an authenticated victim opens the link, attacker-controlled JavaScript can execute with the victim's Sulu-origin session and can read data or perform actions as that victim. This issue is fixed in versions 2.6.25 and 3.0.8.","published":"2026-08-31T21:23:16.852Z","modified":"2026-09-03T03:30:26.277813721Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.6.25"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"3.0.8"}],"fix":{"url":"https://github.com/sulu/sulu/commit/d061094f5b7bb1d5e974544fce30bede9c7adf8e","label":"sulu/sulu@d061094"},"references":[{"type":"WEB","url":"https://github.com/sulu/sulu/releases/tag/2.6.25"},{"type":"WEB","url":"https://github.com/sulu/sulu/releases/tag/3.0.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82396.json"},{"type":"ADVISORY","url":"https://github.com/sulu/sulu/security/advisories/GHSA-pp4x-ccxq-6r33"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82396"},{"type":"FIX","url":"https://github.com/sulu/sulu/commit/d061094f5b7bb1d5e974544fce30bede9c7adf8e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T03:30:26.277813721Z"}}