Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.
This issue has been patched in 17.4.0
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-21T20:43:06Z",
"nvd_published_at": null,
"severity": "MODERATE"
}