CVE-2026-7299
Title: Persistent XSS via unsanitized SQL query editor in Appsmith
XSS
Proof Of Concept
PoC Available for CVE-2026-7299
CWE Category
NVD-CWE-noinfo
Published Date
Jun 02, 2026
Modified Date
Jun 04, 2026
Exploit Status
Available
Score
6.3
CVSS v3.1
Exploit Probability (EPSS)
0.25%
Vulnerability Summary
CVE-2026-7299: Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.
Impacted Vendors
Reference Links
https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit
https://github.com/appsmithorg/appsmith/commit/99d69180919981ed9bc5484050d809a5bec68acc
https://github.com/appsmithorg/appsmith/pull/41666
https://github.com/appsmithorg/appsmith/releases/tag/v2.1
https://github.com/appsmithorg/appsmith/security/advisories/GHSA-vvxf-f8q9-86gh
https://www.kb.cert.org/vuls/id/265691
CVSS v3.1
Source Entity
[email protected]
Severity
MEDIUM
5.4
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
Source Entity
[email protected]
Severity
MEDIUM
6.3
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2026-7299 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Stack
No specific products linked.