External risk intelligence

Stored XSS in Filament Comments Comment Body Rendering

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90943

The vulnerability exists in a comment rendering component used within web applications. While these components are often integrated into public-facing web interfaces, the requirement for authenticated panel access to inject the payload makes public internet exposure contingent on the specific deployment and implementation of the comment system.

Cross-site Scripting

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A stored cross-site scripting vulnerability has been identified in a comment rendering component, allowing authenticated users to inject malicious scripts that can execute in the browsers of other users. This could potentially lead to session token theft and unauthorized actions within affected applications.

  • Malicious scripts can be stored in comments.
  • Could lead to session theft and unauthorized actions.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with existing access to the system can post a comment containing malicious script code. This code remains stored and will execute when other users, including administrators, view the comment, potentially leading to session hijacking or unauthorized actions.

  • Authenticated panel user access required.
  • Stored malicious scripts in comment bodies.
  • Session theft and unauthorized actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated user to inject malicious scripts into comment bodies. When other users, including administrators, view these comments, the scripts could execute in their browsers, potentially leading to session token theft and unauthorized actions. The impact depends on whether the comment feature is publicly accessible and how it's integrated into the application.

  • Authenticated user comments.
  • Malicious scripts execute in user browsers.
  • Unauthorized actions and session theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

The real-world impact of this vulnerability will likely fall to application owners and platform teams responsible for the web applications integrating the affected comment component. The first critical step is to identify all instances of this component, determine if they are accessible to authenticated users and expose sensitive information or administrative functions, and then confirm the specific ownership of each instance to prioritize remediation efforts.

  • Identify accountable application owners.
  • Verify user authentication and reachability.
  • Plan phased updates or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is parallax filament-comments used for?

It is a software component designed for Filament, a popular administration panel framework. Developers integrate it into their web applications to provide commenting features, allowing users to leave notes or feedback directly within the management interface.

What does CWE-79 mean for CVE-2026-90943?

CWE-79 refers to Improper Neutralization of Input During Web Page Generation, commonly known as Stored Cross-Site Scripting (XSS). In this CVE, the software fails to sanitize comment text properly. This lets an attacker save a malicious script as a comment, which then runs automatically in the web browsers of anyone who views that specific comment later.

How does an attacker trigger this vulnerability?

An attacker must have valid credentials to access the application's panel where they can submit comments. The vulnerability is triggered when the malicious code stored in the comment is rendered by the browser of an unsuspecting user or administrator. It is not triggered by simply visiting the page; it requires the interaction of viewing the stored malicious comment.

Do I need to worry if my comments are internal?

Halo Surface Signal indicates that while the vulnerability exists in the rendering component, your risk depends on who can access the comment interface. If the interface is exposed to the internet, unauthorized users with login access pose a higher risk. Even for internal systems, the vulnerability remains dangerous because an authenticated user could target administrative sessions.

What should I do first to address this?

Start by identifying every application in your environment that uses the filament-comments component. Once located, verify which user roles have permission to post comments and assess if those interfaces are reachable by untrusted parties. You should coordinate with your development teams to verify if you are using an affected version and prepare for an update.

References