CVE-2026-9264
Cross-Site Scripting in SketchUp 2026 Dynamic Components
Publication date: 2026-05-22
Last updated on: 2026-05-22
Assigner: Bugcrowd Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trimble | sketchup | 2026 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a cross-site scripting (XSS) issue in SketchUp 2026's Dynamic Components feature. It occurs because the component options window does not properly sanitize input, allowing attackers to craft malicious SKP files. When such a file is opened, the embedded Internet Explorer 11 browser can be exploited to execute arbitrary system commands and read local files without any user interaction.
How can this vulnerability impact me? :
The vulnerability can lead to remote code execution on your system, meaning an attacker could run any commands they choose. Additionally, it allows local file exfiltration, so sensitive files on your computer could be read and stolen without your knowledge or consent.