CVE-2026-7299
CVE-2026-7299
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.
| Vendor | appsmith |
| Product | appsmith |
| Published | Jun 2, 2026 |
| Last Updated | Jun 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for appsmith appsmith
Be the first to know when new medium vulnerabilities affecting appsmith appsmith are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Appsmith / Appsmith
0 < 2.1
References
github.com: https://github.com/appsmithorg/appsmith/security/advisories/GHSA-vvxf-f8q9-86gh github.com: https://github.com/appsmithorg/appsmith/pull/41666 github.com: https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit github.com: https://github.com/appsmithorg/appsmith/releases/tag/v2.1 github.com: https://github.com/appsmithorg/appsmith/commit/99d69180919981ed9bc5484050d809a5bec68acc kb.cert.org: https://www.kb.cert.org/vuls/id/265691