Cross-site scripting in RabbitMQ Server - #VU137254
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's browser session and take over the administrator account.
The vulnerability exists due to cross-site scripting in the management UI connection detail templates when rendering TLS peer certificate subject or issuer fields. A remote user can connect with a specially crafted CA-signed client certificate and cause an administrator to view the connection details page to execute arbitrary JavaScript in an administrator's browser session and take over the administrator account.
Exploitation requires a TLS listener configured with peer verification, the ability to obtain a trusted client certificate with attacker-controlled subject data, and administrator interaction with the connection detail page.