CVE-2026-9264 Details
Description
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.
A cross-site scripting vulnerability has been identified in the Dynamic Components feature of Trimble SketchUp 2026, prior to version 2026.1.3. This vulnerability allows remote code execution and local file exfiltration through maliciously crafted SKP files. The issue arises from improper input sanitization in the component options window, which enables attackers to execute arbitrary system commands and access local files without user interaction by exploiting an embedded Internet Explorer 11 browser.
Users are advised to update SketchUp Desktop to version 2026.1.3 or later. This update will automatically include the patched version of the Dynamic Components extension.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 22, 2026CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://trust.trimble.com/?tcuUid=52252bc0-c196-4b1f-9f13-4e4c9ba247d9 | Bugcrowd Inc. | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Trimble SketchUp | < 2026.1.3 (semver) |
CPE
Remediation
| |
| Trimble Dynamic Components | < 1.8.5 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Bugcrowd Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | New CVE Received | Bugcrowd Inc. |
Volerion