CVE-2026-55696: PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Stored cross-site scripting (XSS) in PrivateBin’s attachment download link. An anonymous attacker can create a paste with a text/html attachment that, with certain user interaction, bypasses protections similar to CVE-2022-24833. When a victim opens the “Download attachment” link in a new tab, the attacker’s inline JavaScript executes in the PrivateBin instance’s origin with full same-origin capability (cookie/localStorage access, same-origin fetch).
This is an incomplete fix of CVE-2022-24833. The original fix only applies to the inline preview blob (in case of SVG), never to the download link’s blob. Thus a text/html (or image/svg) attachment completely bypasses sanitization, re-enabling the exact attack class on instances that don’t enforce the recommended Content-Security-Policy, but with a slightly different attack process.
Instances using the default recommended CSP are protected (the blob inherits script-src ‘self’, blocking inline scripts). The vulnerability affects instances where CSP is weakened, stripped, or absent, which is exactly the defense-in-depth scenario the CVE-2022-24833 fix was meant to cover.
Requires fileupload = true (non-default) and a non-recommended CSP configuration.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55696 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →