STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in src/init.js and public/reauth.html. During the OIDC redirect flow, the error and error_description query parameters returned by the OIDC provider are written directly to the DOM via innerHTML without HTML escaping. An attacker who can craft a malicious redirect URL and convince a user to follow it can execute arbitrary JavaScript in the application's origin context. The vulnerability is most severe when the targeted user has an active STIG Manager session running in another browser tab — injected code executes in the same origin and can communicate with the SharedWorker managing the active access token, enabling authenticated API requests on behalf of the victim including reading and modifying collection data. The vulnerability is patched in version 1.6.8. There is no workaround short of upgrading. Deployments behind a web application firewall that filters reflected XSS payloads in query parameters may have partial mitigation, but this is not a substitute for patching.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-41200, a reflected XSS issue in STIG Manager's OIDC authentication error handling. It contains two files: a README describing the vulnerability, affected versions (1.5.10 through 1.6.7), and usage examples; and a single Python script, cve-2026-41200-poc.py, which is the main exploit entry point. The Python script does not directly attack a live target itself; instead, it generates a malicious OIDC callback URL embedding JavaScript in the error_description parameter. The exploit relies on the target application reflecting error/error_description into the DOM via innerHTML without escaping. The script supports two modes: a higher-impact sharedworker mode and a simpler cookie theft mode. In sharedworker mode, the injected JavaScript instantiates SharedWorker('/worker.js'), listens for a token on the worker port, uses that token to call the STIG Manager API endpoint /api/v1/collections, and exfiltrates the returned data and token to an attacker-controlled /collect endpoint. If that fails, it falls back to sending document.cookie to /fallback. In simple mode, it emits a script that sends document.cookie to /steal on the attacker host. The script accepts configurable callback, API host, and exfiltration host parameters, and can output the result as a raw malicious URL, a curl command, or phishing-style HTML. This makes it an operational PoC rather than a mere detector: it provides ready-to-use payload generation and exfiltration logic, but it is not part of a larger exploitation framework. The primary attack vector is web/browser-based social engineering, requiring a victim to open the crafted URL; successful high-impact exploitation depends on the victim already having an active STIG Manager session.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.