IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also creates another instance of a Cross-Site Scripting (XSS) vulnerability. Version 2.4.28 contains a patch.
References
Configurations
No configuration.
History
05 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-m624-7744-2mhf - |
04 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 21:16
Updated : 2026-06-17 10:48
NVD link : CVE-2026-42538
Mitre link : CVE-2026-42538
CVE.ORG link : CVE-2026-42538
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
