Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
DivvyDrive versions 4.8.2.9 through 4.8.3.1 contain a reflected or stored Cross-Site Scripting (XSS) vulnerability stemming from improper neutralization of script-related HTML tags (CWE-80). Attackers can inject malicious JavaScript code that executes in victims' browsers when they interact with crafted payloads, potentially leading to session hijacking, credential theft, or malware distribution. This vulnerability affects organizations and individuals using DivvyDrive for file sharing and collaboration, with the high CVSS score of 8.8 indicating significant risk requiring immediate patching to version 4.8.3.2 or later.
While this CVE currently maps to zero Casky skills due to the absence of mapped MITRE ATT&ACK techniques, security practitioners using Casky's Claude-powered analysis would benefit from the platform's broader XSS detection capabilities. When analyzing DivvyDrive traffic and logs, practitioners should look for evidence of techniques like T1598 (Phishing) or T1566 (Phishing) if initial compromise vectors are involved, combined with T1059 (Command and Scripting Interpreter) indicators showing JavaScript execution. Casky's extended reasoning engine would help practitioners correlate suspicious HTML tag patterns in user inputs, unencoded script output, and unexpected DOM modifications—enabling them to identify exploitation attempts and validate successful patches before resuming normal operations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-6002. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation