Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
CVE-2026-55630
- No CVSS published and no exploitation signals yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- —
- EchelonGraph score
- Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0%
- EPSS %ILE
- 25%
- KEV
- Not listed
Published
July 6, 2026
Last Modified
September 17, 2026
References (4)
- security-advisories@githubhttps://github.com/kiwitcms/Kiwi/commit/1c2ecc8485faeefd84a526314a0a60d132fbbc09
- security-advisories@githubhttps://github.com/kiwitcms/Kiwi/commit/d5d36e74cf9333cb37e3a8743b22b74dfa9a0139
- security-advisories@githubhttps://github.com/kiwitcms/Kiwi/releases/tag/v16.1
- security-advisories@githubhttps://github.com/kiwitcms/Kiwi/security/advisories/GHSA-473p-56xx-vg67
Vendor Advisories for CVE-2026-55630(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(1)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| pip | kiwitcms | — | ghsa |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
PyPI(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| kiwitcms | 10.0 ... 9.999 (49 versions) | — | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 12× in last 7d / 17× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-17 19:31 UTCEPSS rescore
- 2026-09-17 18:15 UTCGHSA enrichment
- 2026-09-17 16:22 UTCNVD update
- 2026-09-17 15:36 UTCEG score recompute
- 2026-09-17 15:36 UTCGHSA enrichment
- 2026-09-17 15:34 UTCMITRE cvelistV5
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-15 16:35 UTCGHSA enrichment
- 2026-09-15 16:31 UTCNVD update
- 2026-09-15 15:43 UTCGHSA enrichment
- 2026-09-15 15:42 UTCMITRE cvelistV5
- 2026-09-12 03:46 UTCGHSA enrichment
- 2026-09-05 22:56 UTCGHSA enrichment
- 2026-08-30 07:58 UTCGHSA enrichment
- 2026-08-25 12:06 UTCGHSA enrichment
- 2026-08-22 12:22 UTCGHSA enrichment
- 2026-08-19 12:30 UTCGHSA enrichment
- 2026-08-16 12:34 UTCGHSA enrichment
- 2026-08-13 12:52 UTCGHSA enrichment
- 2026-08-10 13:10 UTCGHSA enrichment
- 2026-08-07 13:28 UTCGHSA enrichment
- 2026-08-04 13:47 UTCGHSA enrichment
- 2026-08-01 12:10 UTCEG score recompute
- 2026-08-01 12:10 UTCGHSA enrichment
Show 9 moreShow fewer
- 2026-07-29 12:27 UTCGHSA enrichment
- 2026-07-26 12:45 UTCEG score recompute
- 2026-07-26 12:45 UTCGHSA enrichment
- 2026-07-23 03:20 UTCEG score recompute
- 2026-07-15 21:43 UTCGHSA enrichment
- 2026-07-12 22:01 UTCGHSA enrichment
- 2026-07-09 22:19 UTCGHSA enrichment
- 2026-07-06 22:35 UTCEG score recompute
- 2026-07-06 22:35 UTCGHSA enrichment
Frequently asked(4)
What is CVE-2026-55630?
When was CVE-2026-55630 disclosed?
Is CVE-2026-55630 actively exploited?
How do I remediate CVE-2026-55630?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-55630
Is Your Infrastructure Affected by CVE-2026-55630?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.