CVE-2026-7308

Source
https://cve.org/CVERecord?id=CVE-2026-7308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7308
Published
2026-05-11T17:17:04Z
Modified
2026-09-24T03:45:56Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page
Details

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.

Database specific
{
    "cna_assigner": "Sonatype",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7308.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.6.0"
                },
                {
                    "fixed": "3.92.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "3.6.0"
                },
                {
                    "fixed": "3.92.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/sonatype/nexus-public

Affected ranges

Type
GIT
Repo
https://github.com/sonatype/nexus-public
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "3.93.0"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7308.json"