CVE-2026-7308 PUBLISHED

Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page

Assigner: Sonatype
Reserved: 28.04.2026 Published: 11.05.2026 Updated: 11.05.2026

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Sonatype
Product Nexus Repository
Versions Default: unaffected
  • affected from 3.6.0 to 3.92.0 (excl.)

Credits

  • Ky0toFu finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE