Cross-site scripting in eLabFTW - #VU137349
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary html into the experiment view page.
The vulnerability exists due to cross-site scripting in the experiment view page alert banner when rendering the unescaped locker or timestamper fullname. A remote user can set their display name to a crafted html payload and lock or timestamp a shared experiment to inject arbitrary html into the experiment view page.
User interaction is required to view the affected experiment page.