CVE-2026-32822
dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any unauthenticated attacker can place arbitrary HTML into flash notifications on public routes and rely on the frontend toast component to inject that content into the DOM with `innerHTML`. This creates a reflected DOM XSS that can be delivered with a crafted link to a public page such as `/docs`. Because the vulnerable JavaScript is loaded by the normal application layout, the issue is not limited to a special debug page or an isolated admin-only view.
| CWE | CWE-80 |
| Vendor | datacycle-engine |
| Product | datacycle-core |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Get instant alerts for datacycle-engine datacycle-core
Be the first to know when new medium vulnerabilities affecting datacycle-engine datacycle-core are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N