CVE-2026-76203CWE-180

CVE-2026-76203

published August 19, 2026

CVSS
5.1
EPSS
0%
Percentile
21.1
In the wild
Unconfirmed
What it is

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer

in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound

HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via

CSS hex escapes that reconstruct the url() function and evade the sanitizer blocklist

The record
Technical detail
CVSS
5.1 · NONE
CVSS v4.0
5.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS
0.00289 · 21.1th percentile
Weakness
CWE-180 · Incorrect Behavior Order: Validate Before Canonicalize
Published
2026-08-19T19:18Z
References (2)
EPSS history
Timeline
  • 19 AUG 14:23Z
    CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
    cvelistv5