Cross-site scripting in EspoCRM - CVE-2026-33741
Published: May 11, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser session.
The vulnerability exists due to cross-site scripting in the attachment and image entry points when serving uploaded SVG files as top-level inline documents that can load same-origin external scripts. A remote user can upload a crafted SVG and a second attacker-controlled JavaScript attachment, then trick a victim into opening the SVG to execute arbitrary JavaScript in the victim's browser session.
User interaction is required to open the crafted SVG, and exploitation is reachable through normal attachment-capable fields.