{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flow/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-39915"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flow"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TIM"],"content_html":"\u003cp\u003eTIM Flow versions prior to 26.0.6 contain a CRLF injection vulnerability that allows remote, unauthenticated attackers to inject arbitrary HTTP headers and response body content. The vulnerability stems from the improper sanitization of carriage return (%0D) and line feed (%0A) sequences within the 'rt' URL parameter and the 'access_token' cookie. Because these inputs are reflected directly into 'Set-Cookie' response headers, an attacker can terminate the header block prematurely and inject malicious JavaScript into the response body. This attack vector facilitates Reflected Cross-Site Scripting (XSS), which can be leveraged to hijack authenticated session tokens, exfiltrate sensitive user data, or modify account credentials. Organizations running TIM Flow must upgrade to version 26.0.6 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the execution of arbitrary JavaScript within the context of an authenticated user session. This results in the complete compromise of the user account, including session hijacking and unauthorized changes to account configuration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all instances of TIM Flow to version 26.0.6 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit web application logs for HTTP requests containing encoded newline characters (0x0D0A) within the 'rt' parameter or 'access_token' cookie.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all URL parameters and cookies to block CRLF sequences.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T16:03:15Z","date_published":"2026-08-24T16:03:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-39915/","summary":"TIM Flow versions prior to 26.0.6 contain a CRLF injection vulnerability allowing attackers to inject arbitrary HTTP headers and perform session theft via XSS.","title":"CRLF Injection Vulnerability in TIM Flow","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-39915/"}],"language":"en","title":"CraftedSignal Threat Feed - Flow","version":"https://jsonfeed.org/version/1.1"}