CVE-2026-7308 Details
Description
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.
A stored cross-site scripting vulnerability has been identified in Sonatype Nexus Repository versions 3.6.0 prior to 3.92.0. This issue allows an authenticated user with upload permissions to a hosted repository to inject content that executes arbitrary JavaScript in the browser of any user who views that repository's directory through the HTML index page. As a result, the attacker could perform actions on behalf of the victim within their session.
Users are advised to upgrade to Sonatype Nexus Repository version 3.92.0 or later. For those unable to upgrade immediately, it is recommended to restrict upload permissions on hosted repositories to trusted users and service accounts, and to configure a reverse proxy or web application firewall to block or sanitize requests to the HTML browse endpoint from untrusted networks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-92-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/51592065985939 | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.6.0, < 3.93.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Sonatype |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | Sonatype |