Cross-site scripting in eLabFTW - #VU137348
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary html or css into an exported ELN HTML preview.
The vulnerability exists due to cross-site scripting in comment text and upload filename handling when generating a .eln export preview file. A remote user can supply crafted comment text or an upload filename to inject arbitrary html or css into an exported ELN HTML preview.
User interaction is required to view the generated preview.