What is CVE-2026-42141?
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal infrastructure, access local cloud metadata endpoints (e.g., AWS IMDS), interact with internal services that lack authentication, or exfiltrate data. This vulnerability is fixed in 4.4.1.
Timeline
- 2026-05-12Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
See advisory
Remediation Steps
- Audit all dependencies on TanStack npm package and identify affected versions in software bill of materials (SBOM)
- Update TanStack to patched version and rebuild all dependent applications
- Scan development environments and CI/CD pipelines for malware artifacts from Mini Shai-Hulud campaign
- Review employee device access logs for unauthorized activities corresponding to infection timeline
- Implement npm package integrity verification and code signing validation in supply chain
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of May 2026 (May 18 – 24)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.