Cross-site scripting in eLabFTW - #VU137349

 

Cross-site scripting in eLabFTW - #VU137349

Published: July 12, 2026


Vulnerability identifier: #VU137349
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary html into the experiment view page.

The vulnerability exists due to cross-site scripting in the experiment view page alert banner when rendering the unescaped locker or timestamper fullname. A remote user can set their display name to a crafted html payload and lock or timestamp a shared experiment to inject arbitrary html into the experiment view page.

User interaction is required to view the affected experiment page.


Affected software

eLabFTW

Remediation

Install security update from vendor's website.

eLabFTW - update to 5.6.0

External References

Related Security Bulletins