CVE-2026-7308 | Security Details | Sonatype Guide
CVE-2026-7308
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.
Published Apr 30, 2026
CVSS Score: Medium
Score: 5.1
Security Details
Components Impacted
- Sonatype Research
CVE Details
- CVE ID: CVE-2026-7308
- CWE: CWE-79 Learn more about CWE-79
- Description: An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.
- Published: Apr 30, 2026
CVSS Score & Severity
- Score: 5.1 (Medium)
- CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS Score: 0.060%
Malware
- KEV Status: Not in KEV Catalog: No known exploits
Affected Ecosystems
- Affected
Source
- National Vulnerability Database