CVE-2026-33061: Jexactyl has Stored DOM Cross-Site Scripting (XSS) via unescaped JSON in Blade template
Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80efab628d1241198ea4f079779cfd inject server-side objects into client-side JavaScript through resources/views/templates/wrapper.blade.php. Using unescaped {!! jsonencode(...) !!} without safe encoding flags allows string values to break out of the JavaScript context and be interpreted as HTML/JS by the browser. If any serialized fields contain attacker-controlled content, such as a username, display name, or site config value, a malicious payload will execute arbitrary script for any user viewing the page (stored DOM XSS). This issue has been patched by commit e28edb204e80efab628d1241198ea4f079779cfd.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33061?
CVE-2026-33061 has a high severity due to its potential for stored DOM Cross-Site Scripting vulnerabilities.
How do I fix CVE-2026-33061?
To fix CVE-2026-33061, update your exactyl to a version newer than e28edb204e80efab628d1241198ea4f079779cfd.
What causes CVE-2026-33061?
CVE-2026-33061 is caused by unescaped JSON being injected into Blade templates in exactyl.
Which software versions are affected by CVE-2026-33061?
CVE-2026-33061 affects exactyl versions between 025e8dbb0daaa04054276bda814d922cf4af58da and e28edb204e80efab628d1241198ea4f079779cfd.
Is there a known exploit for CVE-2026-33061?
Yes, CVE-2026-33061 can be exploited by injecting malicious scripts via stored data in exactyl's templating system.