CVE-2026-1337 Details
Description
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
A log injection vulnerability has been identified in Neo4j Enterprise and Community editions prior to 2026.01. This issue arises from inadequate escaping of Unicode characters in the query log, which can lead to cross-site scripting (XSS) if the logs are opened in a tool that interprets them as HTML. Although there is no direct security impact on Neo4j products, this advisory recommends treating the logs as plain text when using versions prior to 2026.01.
Users are advised to update to Neo4j versions 2026.01 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/JoakimBulow/CVE-2026-1337 | Neo4j | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-117 | Improper Output Neutralization for Logs | Neo4j |
Affected Products
| Product | Versions |
|---|---|
| neo4j neo4j | < 2026.01.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Neo4j |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | Initial Analysis | [email protected] |
| Feb 6, 2026 | New CVE Received | Neo4j |