CVE-2026-105090: XSS
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Formbricksto a version that resolves this vulnerability.Fixed in 5.4.4 - Upgrade
Upgrade
Formbricksto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from it?
A workspace member with readWrite permission can exploit the issue by configuring Custom Head Scripts on a survey. Any authenticated user who opens that affected survey may have arbitrary JavaScript executed in their browser session, including users with higher privileges.
Are installations affected by default?
Exploitation requires a workspace member with readWrite permission and the ability to configure a survey's Custom Head Scripts under the vulnerable permission enforcement. The issue affects Formbricks versions before 5.4.4 and version 6 before 6.0.1.
What should be done if an immediate upgrade is not possible?
Restrict readWrite access to trusted workspace members and review surveys for configured Custom Head Scripts. Since the vulnerable behavior allows readWrite members to modify these scripts, treating existing script content as untrusted can help identify potentially affected surveys.
How can administrators tell whether they may already be affected?
Review survey-level Custom Head Scripts, especially changes made by members who had readWrite rather than Manage permission. Affected surveys are those whose configured scripts may have been opened by authenticated users, because the scripts execute in those users' browser sessions.