CVE-2026-7299
בינונית 5.4
תיאור (מקור, אנגלית)
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-8/8/2026
- CWE
- CWE-79
מוצרים מושפעים
appsmith: appsmith
קישורים
- https://github.com/appsmithorg/appsmith/pull/41666 Issue TrackingPatchVendor Advisory
- https://github.com/appsmithorg/appsmith/security/advisories/GHSA-vvxf-f8q9-86gh Vendor Advisory
- https://github.com/appsmithorg/appsmith/commit/99d69180919981ed9bc5484050d809a… Patch
- https://www.kb.cert.org/vuls/id/265691 PatchThird Party Advisory
- https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit ExploitThird Party Advisory
- https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit ExploitThird Party Advisory
- https://github.com/appsmithorg/appsmith/releases/tag/v2.1 Release Notes