Sceawere

Vulnerability Detail

CVE-2026-19988UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Alaev SEO Tools XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Alaev
Product
SEO Tools Extension
Attack Type
Basic Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-17T06:17:39.583Z",
  "pubdate": "2026-08-17T06:17:39.583Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability has been identified in the Alaev SEO Tools Extension for Chrome, specifically affecting versions up to 1.0.10. The flaw resides within the Popup UI component, specifically in the addDiv function located in the src/popup.html file. This security defect allows a remote attacker to execute arbitrary scripts within the context of the extension's popup interface.\nThe impact of this vulnerability includes potential unauthorized access to extension data, manipulation of the Document Object Model (DOM) of the popup, and potential abuse of extension privileges if underlying scripts interact insecurely with sensitive APIs. The exploit is currently public, increasing the risk of opportunistic attacks against users who have installed the affected versions.\nThe vendor was notified of the issue prior to public disclosure but failed to provide a response or remediation. Exploitation can be initiated remotely through malicious manipulation of input handled by the vulnerable function. Due to the lack of vendor patching, users face persistent risk until the extension is updated or removed.",
  "technicalDetails": "The vulnerability is classified as a basic cross-site scripting (XSS) flaw, stemming from improper input validation and unsafe rendering of data within the user interface of the browser extension. The root cause lies in the addDiv function within the src/popup.html file of the Popup UI component, which processes untrusted data without adequate sanitization or context-aware encoding before inserting it into the DOM.\nThe attack flow begins when an attacker crafts a malicious payload designed to exploit the lack of input filtering in the addDiv function. Because the vulnerability is exposed within the extension's popup architecture, the attack can be initiated remotely by tricking the user or leveraging conditions where external, untrusted data is fed into the extension interface. When the vulnerable function processes this input, the payload is dynamically interpreted and executed by the browser engine within the origin of the extension.\nThe affected product is the Alaev SEO Tools Extension on Chrome, covering all versions up to and including 1.0.10. Exploitation does not require prior authentication to the extension, but it relies on the execution context of the Popup UI component. Given that browser extensions often operate with elevated permissions relative to standard web pages, successful execution of cross-site scripting payloads within this environment could lead to extended compromise of extension functionalities, unauthorized data exfiltration, or interaction with browser storage mechanisms accessible to the extension script."
}
CVE-2026-19988: Alaev SEO Tools XSS Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere