CVE-2026-105090
Received Received - Intake

Stored XSS in Formbricks Survey Custom Head Scripts

Vulnerability report for CVE-2026-105090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: MITRE

Description

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
formbricks formbricks to 5.4.4 (inc)
formbricks formbricks to 6.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Formbricks versions before 5.4.4 and 6 before 6.0.1. It occurs because the Custom Head Scripts feature allowed workspace members with only readWrite permission to modify survey scripts, despite documentation requiring Manage permission. This enables attackers to inject malicious JavaScript into survey headers, which executes in the browser sessions of higher-privileged users accessing the survey.

Detection Guidance

Check Formbricks versions for affected releases (before 5.4.4 or 6.0.1). Inspect surveys with Custom Head Scripts configured by non-managers. Review workspace member permissions for unauthorized script modifications.

Impact Analysis

An attacker with readWrite access could inject malicious scripts that run in the sessions of privileged users like owners or managers. This could lead to session hijacking, unauthorized actions on behalf of victims, privilege escalation, or theft of sensitive data such as session cookies or API keys. The impact is limited to self-hosted instances, as Formbricks Cloud is not affected.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized processing of sensitive information, or loss of control over user sessions, potentially leading to non-compliance with these regulations.

Mitigation Strategies

Upgrade Formbricks to versions 5.4.4 or 6.0.1 or later. Ensure only users with Manage permission can modify survey Custom Head Scripts. Review and remove any unauthorized scripts set by lower-privileged members.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart