Cross-site scripting in eLabFTW - #VU137347
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in ELN HTML export when rendering unescaped entity fields. A remote user can inject HTML or JavaScript into an entity title or other entity fields to execute arbitrary script in a victim's browser.
User interaction is required to open the exported HTML document, and the attacker-controlled markup is also bundled as ro-crate-preview.html inside .eln archives.