๐Ÿ” CVE Alert

CVE-2026-82396

MEDIUM 5.4

Sulu: Stored XSS via media download inline-disposition override

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the inline query parameter for scriptable MIME types. The vulnerable stored Content-Type values include text/html, application/xhtml+xml, text/xml, and application/xml. An attacker with media upload permission can store an HTML, XHTML, or XML document and create a link using inline=1, causing the application to return the file on the Sulu origin instead of forcing Content-Disposition attachment. When an authenticated victim opens the link, attacker-controlled JavaScript can execute with the victim's Sulu-origin session and can read data or perform actions as that victim. This issue is fixed in versions 2.6.25 and 3.0.8.

CWE CWE-79
Vendor sulu
Product sulu
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for sulu sulu

Be the first to know when new medium vulnerabilities affecting sulu sulu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

sulu / sulu
< 2.6.25 >= 3.0.0-alpha1, < 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sulu/sulu/security/advisories/GHSA-pp4x-ccxq-6r33 github.com: https://github.com/sulu/sulu/commit/d061094f5b7bb1d5e974544fce30bede9c7adf8e github.com: https://github.com/sulu/sulu/releases/tag/2.6.25 github.com: https://github.com/sulu/sulu/releases/tag/3.0.8