CVE-2026-91775 Overview
CVE-2026-91775 is a stored cross-site scripting (XSS) vulnerability in LimeSurvey. The flaw exists in the survey import workflow where the application fails to safely encode attacker-controlled content extracted from a crafted .lss survey file. When an administrator imports the file and the application displays import warnings, embedded script payloads execute in the administrative interface.
The vulnerability is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation. Exploitation targets authenticated administrators, and successful attacks can compromise the survey platform's back-end management functions.
Critical Impact
Attackers who convince an administrator to import a malicious .lss file can execute arbitrary JavaScript in the admin session, enabling account takeover, survey data theft, and lateral actions within the LimeSurvey control panel.
Affected Products
- LimeSurvey (survey administration interface, import warnings display path)
- Versions prior to the fix committed in c96db80
- Deployments that permit administrators to import external .lss survey files
Discovery Timeline
- 2026-09-23 - CVE-2026-91775 published to the National Vulnerability Database
- 2026-09-23 - Record last modified in NVD
- Vendor patch published in the LimeSurvey repository
- Advisory published by Fluid Attacks
Technical Details for CVE-2026-91775
Vulnerability Analysis
LimeSurvey uses the .lss XML-based format to serialize survey structure, questions, groups, and metadata. When an administrator imports a survey, the parser validates the archive and generates human-readable warning messages for malformed or unexpected fields. These warnings are rendered directly into the administrative HTML view.
The rendering path echoes attacker-supplied values from the .lss file without HTML entity encoding. Any string field parsed during import can carry a script payload that reaches the DOM verbatim. Because the warning banner appears inside an authenticated admin page, the payload executes with the administrator's session context.
The issue is classified as stored XSS: the malicious content persists in the uploaded file and re-executes each time the import warnings are displayed. It does not require an external social engineering vector beyond convincing an administrator to import a survey file.
Root Cause
The root cause is missing output encoding in the import-warning rendering routine. The template concatenates values pulled from the .lss document into HTML output rather than passing them through the framework's HTML-escape helper. This defect maps directly to CWE-79.
Attack Vector
The attack requires network access to the LimeSurvey administrative interface and administrator interaction to trigger the import. An adversary crafts an .lss file whose fields contain HTML or JavaScript payloads. When the administrator imports the file, the warning display renders the payload, executing script in the admin origin. Consult the Fluid Attacks advisory for reproduction details.
Detection Methods for CVE-2026-91775
Indicators of Compromise
- Unexpected .lss files uploaded to LimeSurvey import endpoints, particularly files containing HTML tags, <script> elements, or JavaScript URI schemes in question, group, or metadata fields.
- Administrative sessions performing atypical actions after a survey import, such as new user creation, permission changes, or bulk data export.
- Outbound HTTP requests from administrator browsers to unfamiliar domains immediately following an import operation.
Detection Strategies
- Inspect stored .lss archives for embedded HTML or script content in text fields before allowing import.
- Enable web server access logging on the LimeSurvey admin import routes and review requests to import and warning-display endpoints.
- Deploy a web application firewall rule that flags multipart uploads whose XML payloads contain <script, onerror=, or javascript: tokens.
Monitoring Recommendations
- Alert on administrator account activity that deviates from historical baselines, including session token reuse from new IP addresses.
- Monitor LimeSurvey audit logs for import events followed by privilege or configuration changes within a short window.
- Forward LimeSurvey and reverse-proxy logs to a centralized analytics platform to correlate import events with subsequent admin API calls.
How to Mitigate CVE-2026-91775
Immediate Actions Required
- Apply the upstream fix from commit c96db80 or upgrade to the LimeSurvey release that incorporates it.
- Restrict survey import capability to a small, trusted set of administrators until patching is complete.
- Audit recent imports and review administrator activity for signs of session abuse.
Patch Information
The LimeSurvey project fixed the flaw in commit c96db8093e852eb8b1a2ebbb32478d6fb34cb651, which adds proper HTML encoding to the import warning display. Track the LimeSurvey repository for the corresponding tagged release and apply it to all production and staging instances.
Workarounds
- Block .lss uploads at the reverse proxy or WAF until the patch is deployed.
- Require administrators to review .lss file contents in a text editor before importing when patching cannot be immediate.
- Enforce a strict Content Security Policy on the admin interface to reduce the impact of injected inline scripts.
# Example NGINX rule to block .lss uploads to the LimeSurvey admin path
location /index.php {
if ($request_method = POST) {
if ($http_content_type ~* "multipart/form-data") {
set $block_lss 1;
}
}
# Combine with a WAF rule that inspects the multipart body
# for the string ".lss" in the filename parameter and returns 403
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
