Vulnerability Description
OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through malicious research topic inputs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Algonet | Orcastatllm Researcher | 1 |
Related Weaknesses (CWE)
References
- https://github.com/AlgoNetLab/OrcaStatLLM-Researcher/security/advisories/GHSA-47ExploitVendor Advisory
FAQ
What is CVE-2026-24903?
CVE-2026-24903 is a vulnerability with a CVSS score of 5.4 (MEDIUM). OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that...
How severe is CVE-2026-24903?
CVE-2026-24903 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24903?
Check the references section above for vendor advisories and patch information. Affected products include: Algonet Orcastatllm Researcher.