A stored Cross-Site Scripting (XSS) vulnerability exists in the Mercator open-source web application (information system mapping) in versions prior to 2026.02.22. The issue is caused by use of unescaped Laravel Blade output directives ({!! !!}) in display templates, allowing attacker-controlled content to be rendered without HTML/JS escaping. An authenticated user with the User role can inject arbitrary JavaScript payloads into entity fields (e.g., the "contact point" field) when creating or editing entities; the payload is then stored and executed in the browser context of any user who later views the affected page, including administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
{!! !!}) with escaped output ({{ }}) in affected display templates; apply strict server-side validation and output encoding for user-supplied fields rendered in HTML; consider deploying a restrictive Content Security Policy (CSP) to reduce XSS impact; and limit which roles can edit fields that are rendered to other users until patched.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository provides two operational PoCs for CVE-2026-27639 affecting the Mercator web application, leveraging stored XSS to perform privileged actions in an admin’s browser session. Structure: - README.md: Describes the two PoCs (account takeover and privilege escalation) and provides a Docker-based vulnerable lab setup for Mercator 2026.02.09, plus links to CVE/advisory. - account_takeover/: - poc_account_takeover.py: Orchestrator. Logs in as attacker, starts a local HTTP server to host a patched JS payload and receive debug beacons, then injects a stored XSS payload into an Entity’s contact_point field. Waits for an admin to trigger the XSS. - account_takeover.js: Browser payload executed in victim context. Reads CSRF token from a meta tag, fetches /admin/users/<adminId>/edit to scrape required form fields and roles, then submits an update to /admin/users/<adminId> to set a new password for the target admin user. Uses navigator.sendBeacon to report progress to attacker callback at /dbg. - privesc/: - poc_privesc.py: Similar orchestrator. Logs in, serves privesc.js, injects stored XSS into an Entity, and waits for admin trigger. - privesc.js: Browser payload. Enumerates /admin/users to find the attacker’s user ID, fetches /admin/users/<uid>/edit to extract CSRF token and the option value for the 'Admin' role, then submits an update to /admin/users/<uid> assigning the Admin role. Key capabilities: - Stored XSS injection via creating an admin Entity with a <script src=...> tag. - Account takeover by resetting the admin password (requires admin to execute payload). - Privilege escalation by granting the attacker account the Admin role (requires admin to execute payload). Notable operational details: - Both PoCs require attacker credentials to inject the stored XSS. - Success depends on an admin later viewing the injected content. - The account takeover PoC includes a callback/beacon channel for step-by-step telemetry; the privesc PoC does not include explicit beaconing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.