wid-sec-w-2026-1028
·
Published 2026-04-08
·
View on BSI CERT-Bund ↗
Sonatype Nexus Repository Manager: Vulnerability allows Cross-Site Scripting
CVSS N/A
NONE
Risk Summary
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
CVEs (1)
Affected Vendors
Sonatype
Affected Products (2)
Sonatype
·
Nexus Repository Manager
<3.91.0
Sonatype
·
Nexus Repository Manager
3.91.0
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more