What is CVE-2026-72583?
CVE-2026-72583 is a stored XSS vulnerability in fastschema through version 0.15.1. It allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME type allow-list check. Affected users should update to the latest version immediately.
Azərbaycanca: CVE-2026-72583, fastschema-nın v0.15.1-ə qədər olan versiyalarında saxlanılan XSS zəifliyidir. Bu, aşağı səlahiyyətli autentifikasiya olunmuş istifadəçiyə MIME tipi yoxlanışını keçərək zərərli JavaScript ehtiva edən SVG faylı yükləməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal ən son versiyaya yeniləmə aparmalıdırlar.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What versions of fastschema are affected by CVE-2026-72583?
This stored XSS vulnerability affects fastschema through version 0.15.1.
How can an attacker exploit CVE-2026-72583?
A low-privileged authenticated user can exploit it by uploading an SVG file containing malicious JavaScript, bypassing the MIME type allow-list check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.