CVE-2026-5615 is a cross-site scripting vulnerability affecting givanz VvvebJs up to and including version 2.0.5. The issue is in the upload.php file upload endpoint, where manipulation of the uploadAllowExtensions argument allows an attacker to upload an SVG file that is then rendered in a way that results in stored XSS. Supporting context indicates the vulnerable behavior is specifically tied to SVG being permitted as an uploadable extension, and the fixing commit 8cac22cff99b8bc701c408aa8e887fa702755336 removed SVG from the allowed extensions list. The vulnerability is remotely exploitable and public exploit information is available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python 2 proof-of-concept for a claimed stored XSS vulnerability in VvvebJs <= 2.0.5. The main file, CVE-2026-5615.py, reads a user-supplied list of target base URLs, then uses a 10-thread pool to test each target. For each host it constructs target/upload.php, submits a handcrafted multipart/form-data POST containing an SVG file, parses the server response for a returned .svg path, then performs a GET request to the uploaded file to confirm that the SVG is publicly accessible and still contains the unsanitized onload JavaScript handler. If successful, it prints the final URL and appends the target and uploaded file URL to SAHMSEC-CVE-2026-5615_Exploited.txt. The payload is not a shell or RCE payload; it is a browser-executed stored XSS demonstration using alert(document.domain). The repository also includes a large text file of candidate targets (CVE-2026-5615.txt), indicating intended batch scanning/exploitation, and a README describing usage and mitigation. The exploit is operational but basic: hardcoded endpoint (/upload.php), hardcoded SVG payload, disabled TLS verification, and simple regex-based response parsing.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.