CVE-2026-7308
Received
Received - Intake
Stored XSS in Sonatype Nexus Repository via HTML Index
Publication date: 2026-05-11
Last updated on: 2026-05-11
Assigner: Sonatype
Description
Description
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonatype | nexus_repository | From 3.6.0 (inc) to 3.92.0 (exc) |
| sonatype | nexus_repository | From 3.6.0 (inc) to 3.91.x (inc) |
| sonatype | nexus_repository | 3.92.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |