THREAT OPS › Threat News › [GHSA] GHSA-f2xf-7x3g-4272 (medium) — PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
[GHSA] GHSA-f2xf-7x3g-4272 (medium) — PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
GHSA-f2xf-7x3g-4272 Severity: medium CVE: CVE-2026-55696
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
### Summary
Stored cross-site scripting (XSS) in PrivateBin's attachment download link. An anonymous attacker can create a paste with a **text/html** attachment that, with certain user interact
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-55696cve
- CVE-2022-24833cve
- http://instance/...**url
- https://privatebin.info/reports/vulnerability-2022-04-09.htmlurl
- http://127.0.0.1:8099/**url
- http://127.0.0.1:8099/...**url
- http://127.0.0.1:8099url
- https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Same-origin_policy#cross-origin_data_storage_accessurl
Original source: https://github.com/advisories/GHSA-f2xf-7x3g-4272