[Japanese]

JVNDB-2026-000130

Multiple vulnerabilities in SHIRASAGI

Overview

SHIRASAGI provided by SHIRASAGI Project contains multiple vulnerabilities listed below.
  • Cross-site scripting (CWE-79) - CVE-2026-81635
  • Authorization bypass (CWE-639) - CVE-2026-82582
CVE-2026-81635
Tonosaki Aoba of Tokyo Denki University remote control Laboratory reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-82582
Kuniyoshi Noguchi @KuniNogu remote control Laboratory reported these vulnerabilities to SHIRASAGI Project and IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.4 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 5.1 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): Passive
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): Low
  • Integrity Impact (SI): Low
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-81635


CVSS v3 Severity
Base Metrics: 4.3(Medium) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : Low
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : Low
  • Integrity Impact : None
  • Availability Impact : None
CVSS v4 Severity
Base Metrics: 5.3 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): Low
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-82582
Affected Products


SHIRASAGI Project
  • SHIRASAGI v1.14.0 to v1.20.2 (CVE-2026-81635)
  • SHIRASAGI v1.20.2 and earlier (CVE-2026-82582)

Impact

  • An arbitrary script may be executed on the web browser of a user who accesses a website using the affected product (CVE-2026-81635).
  • Unauthorized users may be able to retrieve files from the groupware's shared file feature (CVE-2026-82582).
Solution

[Update the software]
Update the software to the latest version according to the information provided by the developer.
The developer has released the following version that addresses these vulnerabilities.
  • SHIRASAGI v1.21.0
Vendor Information

SHIRASAGI Project
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
  2. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-81635
  2. CVE-2026-82582
References

  1. JVN : JVN#37476837
Revision History

  • [2026/09/10]
      Web page was published