CVE-2026-7308 | Security Details | Sonatype Guide

CVE-2026-7308

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.

Published Apr 30, 2026

CVSS Score: Medium
Score: 5.1

Security Details

Components Impacted

CVE Details

CVSS Score & Severity

Malware

Affected Ecosystems

Source

References